CVE-2011-0881
published 2011-07-20CVE-2011-0881: Unspecified vulnerability in the EMCTL component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7, and Oracle Enterprise Manager Grid Control…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.96%
57.9th percentile
Unspecified vulnerability in the EMCTL component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect integrity via unknown vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | enterprise_manager_grid_control | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f88x-pmr8-x5x7: Unspecified vulnerability in the EMCTL component in Oracle Database Server 10
ghsa_unreviewed·2022-05-17
CVE-2011-0881 [MEDIUM] GHSA-f88x-pmr8-x5x7: Unspecified vulnerability in the EMCTL component in Oracle Database Server 10
Unspecified vulnerability in the EMCTL component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect integrity via unknown vectors.
Red Hat
xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)
vendor_redhat·2014-07-08·CVSS 7.5
CVE-2012-0881 [HIGH] CWE-407 xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)
xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
Statement: This issue affects the versions of xerces as shipped with Red Hat Enterprise Linux 6. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: xerces-j2 (Red Hat Enterprise Linux 5) - Affected
Package: xerces-j2 (Red Hat Enterprise Linux 6) - Affected
Package: xerces-j2 (Red Hat JBoss Enterprise Web Server 1) - Affect
Red Hat
jabberd: DoS via the XML "billion laughs attack"
vendor_redhat·2011-05-31·CVSS 6.5
CVE-2011-1755 [MEDIUM] jabberd: DoS via the XML "billion laughs attack"
jabberd: DoS via the XML "billion laughs attack"
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Statement: Vulnerable. This issue has been addressed in Red Hat Network Satellite Server v 5.4.1 via RHSA-2011:0882 https://rhn.redhat.com/errata/RHSA-2011-0882.html and in Red Hat Network Proxy Server v5.4.1 via RHSA-2011:0881 https://rhn.redhat.com/errata/RHSA-2011-0881.html. This issue is not planned
to be fixed in Red Hat Network Satellite Server versions 5.0.2, 5.1.1, 5.2.1, 5.3.0 and not planned to be fixed in Red Hat Network Proxy Server versions 5.0.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4966 freeradius: does not respect expired passwords when using the unix module
bugzilla·2012-11-21·CVSS 6.0
CVE-2011-4966 [MEDIUM] CVE-2011-4966 freeradius: does not respect expired passwords when using the unix module
CVE-2011-4966 freeradius: does not respect expired passwords when using the unix module
When FreeRADIUS is configured to use the 'unix' module and shadow passwords, the password expiration field is ignored. This could allow a user with an expired password to authenticate against FreeRADIUS.
This was corrected upstream:
https://github.com/alandekok/freeradius-server/commit/1b1ec5ce75e224bd1755650c18ccdaa6dc53e605
And was also corrected in Red Hat Enterprise Linux 6 via RHBA-2012:0881:
https://rhn.redhat.com/errata/RHBA-2012-0881.html
Statement:
(none)
Discussion:
This issue affects the version of freeradius and freeradius2 as shipped with Red Hat Enterprise Linux 5.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0134 https://rh
Bugzilla
CVE-2012-0881 xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)
bugzilla·2012-02-03·CVSS 7.5
CVE-2012-0881 [HIGH] CVE-2012-0881 xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)
CVE-2012-0881 xml: xerces-j2 hash table collisions CPU usage DoS (oCERT-2011-003)
Juraj Somorovsky reported that certain XML parsers/servers are affected by the
same, or similar, flaw as the hash table collisions CPU usage denial of
service. Sending a specially crafted message to an XML service can result in
longer processing time, which could lead to a denial of service. It is
reported that this attack on XML can be applied on different XML nodes (such as
entities, element attributes, namespaces, various elements in the XML security,
etc.).
xerces-j2 is written in Java and makes significant use of arrays.
Discussion:
Statement:
This issue affects the versions of xerces as shipped with Red Hat Enterprise Linux 6. Red Hat Product Security has rated this issue as having Moderate securit
2011-07-20
Published