CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2011-3528

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 8.9 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to eProfile.

    Published: 18 Oct 2011
    4
    Medium

    CVE-2011-3529

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.0 and 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Talent Acquisition Manager.

    Published: 18 Oct 2011
    4
    Medium

    CVE-2011-3530

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 8.9 allows remote authenticated users to affect confidentiality via unknown vectors related to eDevelopment.

    Published: 18 Oct 2011
    5
    Medium

    CVE-2011-3534

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Network Status Monitor (statd).

    Published: 18 Oct 2011
    5
    Medium

    CVE-2011-3535

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Solaris component in Oracle Sun Products Suite 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Remote Quota Server (rquotad).

    Published: 18 Oct 2011
    2.1
    Low

    CVE-2011-3536

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability, related to DTrace Software Library (libdtrace).

    Published: 18 Oct 2011
    7.8
    High

    CVE-2011-3537

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel/Filesystem.

    Published: 18 Oct 2011
    6.8
    Medium

    CVE-2011-3538

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Sun Ray component in Oracle Virtualization 4.0 allows remote attackers to affect integrity, related to Authentication. NOTE: this identifier was inadvertently used for an Oracle Industry Applications issue involving TMS Help, but that issue has been assigned CVE-2011-2323.

    Published: 18 Oct 2011
    1.7
    Low

    CVE-2011-3539

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability via unknown vectors related to Zones.

    Published: 18 Oct 2011
    7.8
    High

    CVE-2011-3543

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availability, related to iSCSI DataMover (IDM).

    Published: 18 Oct 2011
    4.3
    Medium

    CVE-2011-2309

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Health Sciences - Oracle Clinical, Remote Data Capture component in Oracle Industry Applications 4.6 and 4.6.2 allows remote attackers to affect integrity, related to RDC Help.

    Published: 18 Oct 2011
    2.1
    Low

    CVE-2011-2327

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Communications Unified component in Oracle Sun Products Suite 7.0 allows local users to affect confidentiality via unknown vectors related to Delegated Administrator.

    Published: 18 Oct 2011
    4.9
    Medium

    CVE-2011-3510

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.3.0 and 11.1.1.5.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to BI Platform Security.

    Published: 18 Oct 2011
    5.5
    Medium

    CVE-2011-3518

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel Core - UIF Client component in Oracle Siebel CRM 8.0.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to User Interface.

    Published: 18 Oct 2011
    2.1
    Low

    CVE-2011-3522

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in SysFW 8.0 on certain SPARC T3, Netra SPARC T3, Sun Fire, and Sun Blade based servers allows local users to affect confidentiality, related to Integrated Lights Out Manager CLI.

    Published: 18 Oct 2011
    6.5
    Medium

    CVE-2011-3525

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Application Express component in Oracle Database Server 3.2 and 4.0 allows remote authenticated users to affect confidentiality, integrity, and availability, related to APEX developer user.

    Published: 18 Oct 2011
    5.5
    Medium

    CVE-2011-3533

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 8.9 allows remote authenticated users to affect confidentiality and integrity, related to Job Profile Manager (JPM).

    Published: 18 Oct 2011
    4.9
    Medium

    CVE-2011-3542

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability via unknown vectors related to Kernel/Performance Counter BackEnd Module (pcbe).

    Published: 18 Oct 2011
    5.5
    Medium

    CVE-2011-2306

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Linux 4 and 5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to "Oracle validated."

    Published: 18 Oct 2011
    7.5
    High

    CVE-2011-2310

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Waveset component in Oracle Sun Products Suite 8.1.0 and 8.1.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to User Administration.

    Published: 18 Oct 2011
    1.5
    Low

    CVE-2011-2318

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4.0, 10.0.2.0, 10.3.3.0, 10.3.4.0, and 10.3.5.0 allows local users to affect confidentiality, related to WLS Security.

    Published: 18 Oct 2011
    5
    Medium

    CVE-2011-3532

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Agile Product Supplier Collaboration for Process component in Oracle Supply Chain Products Suite 5.2.2, 6.0.0.2, 6.0.0.3, and 6.0.0.4 allows remote attackers to affect confidentiality via unknown vectors related to Supplier Portal.

    Published: 18 Oct 2011
    1.9
    Low

    CVE-2011-3541

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows local users to affect availability via unknown vectors related to Outside In Filters.

    Published: 18 Oct 2011
    6.9
    Medium

    CVE-2011-4061

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header.

    Published: 18 Oct 2011
    3.3
    Low

    CVE-2011-4060

    Last Modified: 11 Apr 2025

    The runtime linker in QNX Neutrino RTOS 6.5.0 before Service Pack 1 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environment variables when a program is spawned from a setuid program, which allows local users to overwrite files via a symlink attack.

    Published: 18 Oct 2011
    7.2
    High

    CVE-2011-4062

    Last Modified: 11 Apr 2025

    Buffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or possibly gain privileges via a bind system call with a long pathname for a UNIX socket.

    Published: 18 Oct 2011
    1.2
    Low

    CVE-2011-4028

    Last Modified: 11 Apr 2025

    The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.

    Published: 18 Oct 2011
    6.4
    Medium

    CVE-2011-3560

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity, related to JSSE.

    Published: 18 Oct 2011
    7.8
    High

    CVE-2011-1527

    Last Modified: 11 Apr 2025

    The kdb_ldap plugin in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.1, when the LDAP back end is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a kinit operation with incorrect string case for the realm, related to the is_principal_in_realm, krb5_set_error_message, krb5_ldap_get_principal, and process_as_req functions.

    Published: 18 Oct 2011
    4.3
    Medium

    CVE-2011-3506

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle OpenSSO component in Oracle Sun Products Suite 7.1 and 8.0 allows remote attackers to affect integrity via unknown vectors related to Authentication.

    Published: 18 Oct 2011
    7.6
    High

    CVE-2011-3516

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

    Published: 18 Oct 2011
    5.8
    Medium

    CVE-2011-3546

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity via unknown vectors related to Deployment.

    Published: 18 Oct 2011
    10
    Critical

    CVE-2011-3549

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing.

    Published: 18 Oct 2011
    7.6
    High

    CVE-2011-3550

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to AWT.

    Published: 18 Oct 2011
    9.3
    Critical

    CVE-2011-3551

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

    Published: 18 Oct 2011
    2.6
    Low

    CVE-2011-3552

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote attackers to affect integrity via unknown vectors related to Networking.

    Published: 18 Oct 2011
    6.1
    Medium

    CVE-2011-3555

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE, and 7 allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity and availability via unknown vectors.

    Published: 18 Oct 2011
    5
    Medium

    CVE-2011-3558

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to HotSpot.

    Published: 18 Oct 2011
    7.8
    High

    CVE-2011-1528

    Last Modified: 11 Apr 2025

    The krb5_ldap_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when the LDAP back end is used, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors, related to the locked_check_p function. NOTE: the Berkeley DB vector is covered by CVE-2011-4151.

    Published: 18 Oct 2011
    7.8
    High

    CVE-2011-3517

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle OpenSSO component in Oracle Sun Products Suite 8.0 allows remote attackers to affect availability via unknown vectors related to Authentication.

    Published: 18 Oct 2011
    10
    Critical

    CVE-2011-3545

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.

    Published: 18 Oct 2011
    5
    Medium

    CVE-2011-3547

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Networking.

    Published: 18 Oct 2011
    10
    Critical

    CVE-2011-3548

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to AWT.

    Published: 18 Oct 2011
    7.5
    High

    CVE-2011-3556

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3557.

    Published: 18 Oct 2011
    1.8
    Low

    CVE-2011-3561

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.

    Published: 18 Oct 2011
    1.9
    Low

    CVE-2011-4029

    Last Modified: 11 Apr 2025

    The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a temporary lock file.

    Published: 18 Oct 2011
    7.8
    High

    CVE-2011-4151

    Last Modified: 11 Apr 2025

    The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4, when the db2 (aka Berkeley DB) back end is used, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors, a different vulnerability than CVE-2011-1528.

    Published: 18 Oct 2011
    9.8
    Critical

    CVE-2011-3544

    Last Modified: 22 Apr 2026

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

    Published: 18 Oct 2011
    7.8
    High

    CVE-2011-1529

    Last Modified: 11 Apr 2025

    The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when the db2 (aka Berkeley DB) or LDAP back end is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger certain process_as_req errors.

    Published: 18 Oct 2011
    10
    Critical

    CVE-2011-3521

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE, 7, 6 Update 27 and earlier, and 5.0 Update 31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deserialization.

    Published: 18 Oct 2011