CVE-2011-0830
published 2011-07-20CVE-2011-0830: Unspecified vulnerability in the Event Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, and 10.2.0.4, and Oracle Enterprise Manager Grid…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.57%
72.8th percentile
Unspecified vulnerability in the Event Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, and 10.2.0.4, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect integrity via unknown vectors related to Rules Management UI.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | drupal | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | enterprise_manager_grid_control | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9f9h-c85j-c3hw: Unspecified vulnerability in the Event Management component in Oracle Database Server 10
ghsa_unreviewed·2022-05-17
CVE-2011-0830 [MEDIUM] GHSA-9f9h-c85j-c3hw: Unspecified vulnerability in the Event Management component in Oracle Database Server 10
Unspecified vulnerability in the Event Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, and 10.2.0.4, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect integrity via unknown vectors related to Rules Management UI.
Red Hat
php: remote code exec flaw introduced in the CVE-2011-4885 hashdos fix
vendor_redhat·2012-02-02·CVSS 5.0
CVE-2012-0830 [MEDIUM] CWE-228 php: remote code exec flaw introduced in the CVE-2011-4885 hashdos fix
php: remote code exec flaw introduced in the CVE-2011-4885 hashdos fix
The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.
Drupal
Hash DOS attack prevention with Suhosin needs a .htaccess edit - PSA-2012-001
vendor_drupal·2012-01-11·CVSS 5.0
CVE-2011-4885 [MEDIUM] Hash DOS attack prevention with Suhosin needs a .htaccess edit - PSA-2012-001
Title: Hash DOS attack prevention with Suhosin needs a .htaccess edit - PSA-2012-001
Vulnerability Type: Hash DOS attack prevention with Suhosin needs a .htaccess edit
Description: Advisory ID: DRUPAL-PSA-2012-001 Project: Drupal core Version: 6.x, 7.x Date: 2012-01-11 Security risk: Less critical Exploitable from: Remote Vulnerability: Denial of Service Description Update, June 12th 2012: this advisory is related to flaws in PHP with CVE identifiers CVE-2011-4885 and CVE-2012-0830. Users are encouraged to update the PHP used for their site to a version that is known to fix those vulnerabilities. See below for mitigation techniques if your site runs a version of PHP that doesn't contain those fixes and you cannot change it. PHP is vulnerable to a hash collision denial of service (DOS) at
No detection rules found.
No public exploits indexed.
2011-07-20
Published