CVE-2011-0877
published 2011-07-20CVE-2011-0877: Unspecified vulnerability in the Instance Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, and 10.2.0.4, and Oracle Enterprise Manager Grid…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.49%
71.5th percentile
Unspecified vulnerability in the Instance Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, and 10.2.0.4, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect integrity via unknown vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | enterprise_manager_grid_control | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2p8g-m3cw-wvgq: Unspecified vulnerability in the Instance Management component in Oracle Database Server 10
ghsa_unreviewed·2022-05-17
CVE-2011-0877 [MEDIUM] GHSA-2p8g-m3cw-wvgq: Unspecified vulnerability in the Instance Management component in Oracle Database Server 10
Unspecified vulnerability in the Instance Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, and 10.2.0.4, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect integrity via unknown vectors.
Red Hat
PyXML: hash table collisions CPU usage DoS (oCERT-2011-003)
vendor_redhat·2014-07-08·CVSS 7.5
CVE-2012-0877 [HIGH] CWE-407 PyXML: hash table collisions CPU usage DoS (oCERT-2011-003)
PyXML: hash table collisions CPU usage DoS (oCERT-2011-003)
PyXML: Hash table collisions CPU usage Denial of Service
Statement: This issue affects the versions of xerces as shipped with Red Hat Enterprise Linux 6. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: PyXML (Red Hat Enterprise Linux 5) - Affected
Package: PyXML (Red Hat Enterprise Linux 6) - Affected
No detection rules found.
No public exploits indexed.
Tenable
Verizon 2016 DBIR – Most Interesting Things
blogs_tenable·2016-05-18
Verizon 2016 DBIR – Most Interesting Things
by Andrew Freeborn May 18, 2016
The Verizon Data Breach Investigation Report (DBIR), first published in 2008, is an annual publication that analyzes information security incidents from public and private organizations, with a focus on data breaches. Data breaches continue to have a major financial impact on organizations, as well as an impact on their reputations. Tenable Network Security offers dashboards and Assurance Report Cards (ARCs) that organizations can use to check themselves against the common threats described in the Verizon DBIR. As in previous years, the 2016 DBIR notes that a vast majority of all attacks fall into a few basic patterns. Throughout this and past years’ reports, suggestions are given for monitoring the network for each of these patterns. This dashboard can ass
Tenable
Verizon 2016 DBIR – Most Common Vulnerabilities
blogs_tenable·2016-05-18
Verizon 2016 DBIR – Most Common Vulnerabilities
by Andrew Freeborn May 18, 2016
The Verizon Data Breach Investigation Report (DBIR), first published in 2008, is an annual publication that analyzes information security incidents from public and private organizations, with a focus on data breaches. Data breaches continue to have a major financial impact on organizations, as well as an impact on their reputations. Tenable Network Security offers dashboards and Assurance Report Cards (ARCs) that can assist organizations in meeting many of the recommendations and best practices in the DBIR. As in previous years, the 2016 DBIR notes that a vast majority of all attacks fall into a few basic patterns. Throughout this and past years’ reports, suggestions are given for monitoring the network for each of these patterns. This ARC can assist an org
Bugzilla
CVE-2012-0877 PyXML: hash table collisions CPU usage DoS (oCERT-2011-003)
bugzilla·2012-02-03·CVSS 7.5
CVE-2012-0877 [HIGH] CVE-2012-0877 PyXML: hash table collisions CPU usage DoS (oCERT-2011-003)
CVE-2012-0877 PyXML: hash table collisions CPU usage DoS (oCERT-2011-003)
However upstream PyXML will still be affected
Juraj Somorovsky reported that certain XML parsers/servers are affected by the
same, or similar, flaw as the hash table collisions CPU usage denial of
service. Sending a specially crafted message to an XML service can result in
longer processing time, which could lead to a denial of service. It is
reported that this attack on XML can be applied on different XML nodes (such as
entities, element attributes, namespaces, various elements in the XML security,
etc.).
PyXML is written in Python and makes significant use of arrays. It is unclear if fixing the Python array hash DoS bug (Bz 750555) will completely address this issue however at first glance it would appear to be
2011-07-20
Published