CVE-2011-3508
https://notcve.org/view.php?id=CVE-2011-3508
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect confidentiality, integrity, and availability, related to LDAP library. Vulnerabilidad no especificada en Oracle Solaris 8, 9, 10 y 11 Express permite a atacantes remotos comprometer la confidencialidad, integridad y disponibilidad. Relacionado con la biblioteca LDAP. • http://osvdb.org/76467 http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html http://www.securityfocus.com/bid/50201 https://exchange.xforce.ibmcloud.com/vulnerabilities/70787 •
CVE-2011-3515
https://notcve.org/view.php?id=CVE-2011-3515
Unspecified vulnerability in the Oracle Solaris 10 and 11 Express allows local users to affect integrity and availability via unknown vectors related to Process File System (procfs). Vulnerabilidad no especificada en Oracle Solaris 10 y 11 Express permite a usuarios locales comprometer la integridad y disponibilidad a través de vectores desconocidos relacionados con Process File System (procfs). • http://osvdb.org/76468 http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html http://www.securityfocus.com/bid/50235 https://exchange.xforce.ibmcloud.com/vulnerabilities/70792 •
CVE-2011-2713
https://notcve.org/view.php?id=CVE-2011-2713
oowriter in OpenOffice.org 3.3.0 and LibreOffice before 3.4.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers an out-of-bounds read in the DOC sprm parser. oowriter en OpenOffice.org v3.3.0 y LibreOffice anterior a v3.4.3 permite a atacantes remotos asistidos por un usuario pueden provocar una denegación de servicio (caída) mediante un archivo DOC manipulado que provoca una lectura fuera del límite analizador sintáctico de DOC sprm. • http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068160.html http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068198.html http://lists.opensuse.org/opensuse-updates/2011-10/msg00019.html http://osvdb.org/76178 http://secunia.com/advisories/50692 http://secunia.com/advisories/60799 http://security.gentoo.org/glsa/glsa-201209-05.xml http://www.debian.org/security/2011/dsa-2315 http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml http: • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2008-7300
https://notcve.org/view.php?id=CVE-2008-7300
The labeled networking implementation in Solaris Trusted Extensions in Sun Solaris 10 and OpenSolaris snv_39 through snv_67, when a labeled zone is in the installed state, allows remote authenticated users to bypass a Mandatory Access Control (MAC) policy and obtain access to the global zone. La implementación del enrutado etiquetado ("labeled networking") de Solaris Trusted Extensions de Sun Solaris 10 y OpenSolaris snv_39 hasta la snv_67, si una zona etiquetada se encuentra en el estado "installed", permite a usuarios autenticados remotos evitar la política MAC (Mandatory Access Control) y obtener acceso a la zona global. • http://secunia.com/advisories/31412 http://sunsolve.sun.com/search/document.do?assetkey=1-26-240099-1 http://www.securityfocus.com/bid/30602 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2011-2427 – flash-plugin: critical flaws fixed in APSB11-26
https://notcve.org/view.php?id=CVE-2011-2427
Stack-based buffer overflow in the ActionScript Virtual Machine (AVM) component in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows attackers to execute arbitrary code or cause a denial of service via unspecified vectors. Desbordamiento de búfer basado en pila en el componente ActionScript Virtual Machine (AVM) de Adobe Flash Player antes de v10.3.183.10 en Windows, Mac OS X, Linux y Solaris, y antes de v10.3.186.7 en Android, permite a atacantes remotos ejecutar código de su elección o causar una denegación de servicio a través de vectores desconocidos. • http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00025.html http://secunia.com/advisories/48308 http://www.adobe.com/support/security/bulletins/apsb11-26.html http://www.redhat.com/support/errata/RHSA-2011-1333.html https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14125 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15950 https://access.redhat.com/security/cve/CVE-2011-2427 https://bugzilla.redhat.com • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •