CVE-2011-0794
published 2011-04-20CVE-2011-0794: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5.0 allows local users to affect confidentiality…
PriorityP415medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.39%
31.3th percentile
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5.0 allows local users to affect confidentiality, integrity, and availability, related to File ID SDK. NOTE: the previous information was obtained from the April 2011 CPU. Oracle has not commented on claims from a reliable third party that this issue is in (a) sccut.dll or (b) libsc_ut.so in Outside In 8.3.5.x through 8.3.5.5684, as used when using the CAB file identification functionality to parse OneNote (.onepkg) files and other formats.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | security_agent | — | — |
| oracle | fusion_middleware | — | — |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Security Agent Remote Code Execution Vulnerabilities
vendor_cisco·2011-10-26·CVSS 10.0
CVE-2011-0794 [CRITICAL] Cisco Security Agent Remote Code Execution Vulnerabilities
Cisco Security Agent Remote Code Execution Vulnerabilities
Cisco Security Agent is affected by vulnerabilities that could allow an unauthenticated attacker to perform remote code execution on the affected device. These vulnerabilities are in a third-party library (Oracle Outside In) and are documented in CERT-CC Vulnerability Note VU#520721 at http://www.kb.cert.org/vuls/id/520721
Cisco has released software updates that address these vulnerabilities.
No workaround is available to mitigate these vulnerabilities.
This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-csa.
Note: Effective October 18, 2011, Cisco moved the current list of Cisco Security Advisories and Responses published by Cisco PSIRT. The new location is
Cisco
Oracle Outside In Technology File Processing Arbitrary Code Execution Vulnerability
vendor_cisco·2011-04-20·CVSS 4.4
CVE-2011-0808 [MEDIUM] CWE-94 Oracle Outside In Technology File Processing Arbitrary Code Execution Vulnerability
Oracle Outside In Technology File Processing Arbitrary Code Execution Vulnerability
Oracle Outside In Technology components used by the Oracle Fusion Middleware applications contain a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.
The vulnerability exists due to incorrect processing of Lotus 1-2-3 spreadsheet files (WKS) and Microsoft Cabinet (CAB) files by the affected software. An unauthenticated, remote attacker could exploit this vulnerability by convincing a targeted user to view malicious files using an application that relies upon Outside In Technology libraries. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the user.
Oracle has confirmed the vulnerability and rele
Cisco
Cisco Security Agent Remote Code Execution Vulnerabilities
vendor_cisco
CVE-2011-0794 Cisco Security Agent Remote Code Execution Vulnerabilities
CVE-2011-0794: Cisco Security Agent Remote Code Execution Vulnerabilities
Cisco Security Agent is affected by vulnerabilities that could allow an unauthenticated attacker to perform remote code execution on the affected device. These vulnerabilities are in a third-party library (Oracle Outside In) and are documented in CERT-CC Vulnerability Note VU#520721 at http://www.kb.cert.org/vuls/id/520721 Cisco has released software updates that address these vulnerabilities. No workaround is available to mitigate these vulnerabilities. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-csa . Note: Effective October 18, 2011, Cisco moved the current list of Cisco Security Advisories and Responses published by Cisco PSIRT. The ne
GHSA
GHSA-8xmp-xr2x-xpvp: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8
ghsa_unreviewed·2022-05-17
CVE-2011-0794 [MEDIUM] GHSA-8xmp-xr2x-xpvp: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5.0 allows local users to affect confidentiality, integrity, and availability, related to File ID SDK. NOTE: the previous information was obtained from the April 2011 CPU. Oracle has not commented on claims from a reliable third party that this issue is in (a) sccut.dll or (b) libsc_ut.so in Outside In 8.3.5.x through 8.3.5.5684, as used when using the CAB file identification functionality to parse OneNote (.onepkg) files and other formats.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/44295http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-csahttp://www-01.ibm.com/support/docview.wss?uid=swg21660640http://www.kb.cert.org/vuls/id/520721http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=7009213&sliceId=1&docTypeID=DT_TID_1_1&dialogID=268451045&stateId=0%200%20268449309http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.htmlhttp://www.securityfocus.com/bid/47437http://secunia.com/advisories/44295http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-csahttp://www-01.ibm.com/support/docview.wss?uid=swg21660640http://www.kb.cert.org/vuls/id/520721http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=7009213&sliceId=1&docTypeID=DT_TID_1_1&dialogID=268451045&stateId=0%200%20268449309http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.htmlhttp://www.securityfocus.com/bid/47437
2011-04-20
Published