Show plain JSON{"id": "CVE-2011-3387", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P", "authentication": "SINGLE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2011-09-02T23:55:05.460", "references": [{"url": "http://www.redhat.com/support/errata/RHSA-2011-1265.html", "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/69641", "source": "cve@mitre.org"}, {"url": "https://www-304.ibm.com/support/docview.wss?uid=isg1PM42551", "source": "cve@mitre.org"}, {"url": "http://www.redhat.com/support/errata/RHSA-2011-1265.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/69641", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www-304.ibm.com/support/docview.wss?uid=isg1PM42551", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-20"}]}], "descriptions": [{"lang": "en", "value": "The class file parser in IBM Java 1.4.2 SR13 FP9 allows remote authenticated users to cause a denial of service (memory consumption or an infinite loop) via a crafted attribute length field in a class file, related to validation of a length field at the wrong time, a different vulnerability than CVE-2011-0311."}, {"lang": "es", "value": "El analizador de archivos de clase en IBM Java v1.4.2 SR13 FP9 permite a usuarios remotos autenticados provocar una denegaci\u00f3n de servicio (consumo de memoria o un bucle infinito) a trav\u00e9s de un campo de atributo de longitud modificada en un archivo de clase, relacionado con la validaci\u00f3n de un campo de longitud en el momento equivocado, una vulnerabilidad diferente a CVE-2011-0311."}], "lastModified": "2025-04-11T00:51:21.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:java:1.4.2.13.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F6EA48C2-7EF8-4E2E-A366-DE53B73029F6"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}