CVE-2011-2244
published 2011-07-20CVE-2011-2244: Unspecified vulnerability in the Security Framework component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and…
PriorityP434medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.94%
77.7th percentile
Unspecified vulnerability in the Security Framework component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Enterprise Manager Grid Control 10.1.0.6, 10.2.0.5, and 11.1.0.1; allows remote attackers to affect confidentiality and integrity via unknown vectors related to Authentication.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | enterprise_manager_grid_control | — | — |
| oracle | enterprise_manager_grid_control | — | — |
| oracle | enterprise_manager_grid_control | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qgwg-3632-v4h2: Unspecified vulnerability in the Security Framework component in Oracle Database Server 10
ghsa_unreviewed·2022-05-17
CVE-2011-2244 [MEDIUM] GHSA-qgwg-3632-v4h2: Unspecified vulnerability in the Security Framework component in Oracle Database Server 10
Unspecified vulnerability in the Security Framework component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Enterprise Manager Grid Control 10.1.0.6, 10.2.0.5, and 11.1.0.1; allows remote attackers to affect confidentiality and integrity via unknown vectors related to Authentication.
Red Hat
avahi: daemon infinite loop triggered by an empty UDP packet (CVE-2010-2244 fix regression)
vendor_redhat·2011-01-04·CVSS 4.3
CVE-2011-1002 [MEDIUM] CWE-835 avahi: daemon infinite loop triggered by an empty UDP packet (CVE-2010-2244 fix regression)
avahi: daemon infinite loop triggered by an empty UDP packet (CVE-2010-2244 fix regression)
avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244.
Red Hat
avahi: daemon infinite loop triggered by an empty UDP packet (CVE-2010-2244 fix regression)
vendor_redhat·2011-01-04·CVSS 4.3
CVE-2011-0634 [MEDIUM] CWE-835 avahi: daemon infinite loop triggered by an empty UDP packet (CVE-2010-2244 fix regression)
avahi: daemon infinite loop triggered by an empty UDP packet (CVE-2010-2244 fix regression)
No description is available for this CVE.
Package: avahi (Red Hat Enterprise Linux 5) - Affected
Package: avahi (Red Hat Enterprise Linux 6) - Affected
No detection rules found.
No public exploits indexed.
2011-07-20
Published