CVE-2012-0107
published 2012-10-16CVE-2012-0107: Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote attackers to affect…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.16%
63.8th percentile
Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote attackers to affect availability via unknown vectors related to Web.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | fusion_middleware | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7c2r-45hm-852f: Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10
ghsa_unreviewed·2022-05-04
CVE-2012-0107 [MEDIUM] GHSA-7c2r-45hm-852f: Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10
Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote attackers to affect availability via unknown vectors related to Web.
Red Hat
kernel: jbd2: unmapped buffer with _Unwritten or _Delay flags set can lead to DoS
vendor_redhat·2012-01-25·CVSS 4.9
CVE-2011-4086 [MEDIUM] kernel: jbd2: unmapped buffer with _Unwritten or _Delay flags set can lead to DoS
kernel: jbd2: unmapped buffer with _Unwritten or _Delay flags set can lead to DoS
The journal_unmap_buffer function in fs/jbd2/transaction.c in the Linux kernel before 3.3.1 does not properly handle the _Delay and _Unwritten buffer head states, which allows local users to cause a denial of service (system crash) by leveraging the presence of an ext4 filesystem that was mounted with a journal.
Statement: This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0107.html, https://rhn.redhat.com/errata/RHSA-2012-0571.html, and https://rhn.redhat.com/errata/RHSA-2012-0670.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/updates/errata/, theref
Red Hat
kernel: possible privilege escalation via SG_IO ioctl
vendor_redhat·2011-12-22·CVSS 4.6
CVE-2011-4127 [MEDIUM] CWE-284 kernel: possible privilege escalation via SG_IO ioctl
kernel: possible privilege escalation via SG_IO ioctl
The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.
Statement: This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4,
5, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0107.html, https://rhn.redhat.com/errata/RHSA-2011-1849.html, and https://rhn.redhat.com/errata/RHSA-2012-0333.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/upda
Red Hat
kernel: ext4: ext4_ext_insert_extent() kernel oops
vendor_redhat·2011-09-28·CVSS 4.0
CVE-2011-3638 [MEDIUM] kernel: ext4: ext4_ext_insert_extent() kernel oops
kernel: ext4: ext4_ext_insert_extent() kernel oops
fs/ext4/extents.c in the Linux kernel before 3.0 does not mark a modified extent as dirty in certain cases of extent splitting, which allows local users to cause a denial of service (system crash) via vectors involving ext4 umount and mount operations.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not include support for EXT4 filesystem. It did not affect the Linux kernel as shipped with Red Hat Enterprise MRG as it has backported the upstream commit 667eff35 that addressed this issue. This has been addressed in Red Hat Enterprise Linux 5 and 6 via https://rhn.redhat.com/errata/RHSA-2012-0107.html and https://rhn.redhat.com/errata/RHSA-2011-1530.html.
Package: kern
Red Hat
kernel: futex: clear robust_list on execve
vendor_redhat·2008-11-15·CVSS 7.2
CVE-2012-0028 [HIGH] kernel: futex: clear robust_list on execve
kernel: futex: clear robust_list on execve
The robust futex implementation in the Linux kernel before 2.6.28 does not properly handle processes that make exec system calls, which allows local users to cause a denial of service or possibly gain privileges by writing to a memory location in a child process.
Statement: This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not have support for robust futexes. It did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG as they have the backported fixes. This has been addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2012-0107.html.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package:
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-10-16
Published