CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2011-4340

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author privileges to inject arbitrary web script or HTML via (1) the profile parameter to extensions/profiledevkit/content/content.profile.php, as demonstrated via requests to (a) the default URI, (b) about/, or (c) drafts/; or (2) the filter parameter in symphony/lib/core/class.symphony.php, as demonstrated via requests to (d) symphony/publish/comments or (e) symphony/publish/images. NOTE: some of these details are obtained from third party information.

    Published: 12 Feb 2012
    4.3
    Medium

    CVE-2011-4341

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author permissions to execute arbitrary SQL commands via the filter parameter to (1) symphony/publish/comments or (2) symphony/publish/images. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks via error messages. NOTE: some of these details are obtained from third party information.

    Published: 12 Feb 2012
    5
    Medium

    CVE-2012-0845

    Last Modified: 11 Apr 2025

    SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an XML-RPC POST request that contains a smaller amount of data than specified by the Content-Length header.

    Published: 12 Feb 2012
    4.3
    Medium

    CVE-2012-0834

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.

    Published: 11 Feb 2012
    5
    Medium

    CVE-2012-1596

    Last Modified: 11 Apr 2025

    The mp2t_process_fragmented_payload function in epan/dissectors/packet-mp2t.c in the MP2T dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a packet containing an invalid pointer value that triggers an incorrect memory-allocation attempt.

    Published: 11 Feb 2012
    4.3
    Medium

    CVE-2011-4038

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 10 Feb 2012
    9.3
    Critical

    CVE-2011-4039

    Last Modified: 11 Apr 2025

    Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation."

    Published: 10 Feb 2012
    7.5
    High

    CVE-2011-4533

    Last Modified: 11 Apr 2025

    zenAdminSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted packet to TCP port 50777, aka Reference Number 25240.

    Published: 10 Feb 2012
    7.5
    High

    CVE-2011-4534

    Last Modified: 11 Apr 2025

    ZenSysSrv.exe in Ing. Punzenberger COPA-DATA zenon 6.51 SP0 allows remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via a series of connections and disconnections on TCP port 1101, aka Reference Number 25212.

    Published: 10 Feb 2012
    4.3
    Medium

    CVE-2012-1046

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0696.

    Published: 10 Feb 2012
    3.3
    Low

    CVE-2012-1593

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-ansi_a.c in the ANSI A dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet.

    Published: 10 Feb 2012
    7.5
    High

    CVE-2012-0452

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger failure of an nsXBLDocumentInfo::ReadPrototypeBindings function call, related to the cycle collector's access to a hash table containing a stale XBL binding.

    Published: 10 Feb 2012
    7.5
    High

    CVE-2011-3955

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors that trigger the aborting of an IndexedDB transaction.

    Published: 9 Feb 2012
    6.8
    Medium

    CVE-2011-3956

    Last Modified: 11 Apr 2025

    The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension.

    Published: 9 Feb 2012
    7.5
    High

    CVE-2011-3957

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the garbage-collection functionality in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving PDF documents.

    Published: 9 Feb 2012
    6.8
    Medium

    CVE-2011-3958

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a column span, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

    Published: 9 Feb 2012
    7.5
    High

    CVE-2011-3959

    Last Modified: 11 Apr 2025

    Buffer overflow in the locale implementation in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 9 Feb 2012
    4.3
    Medium

    CVE-2011-3962

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.46 does not properly perform path clipping, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 9 Feb 2012
    5
    Medium

    CVE-2011-3963

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.46 does not properly handle PDF FAX images, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 9 Feb 2012
    5.8
    Medium

    CVE-2011-3964

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.46 does not properly implement the drag-and-drop feature, which makes it easier for remote attackers to spoof the URL bar via unspecified vectors.

    Published: 9 Feb 2012
    5
    Medium

    CVE-2011-3965

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.46 does not properly check signatures, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 9 Feb 2012
    5
    Medium

    CVE-2011-3967

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) via a crafted certificate.

    Published: 9 Feb 2012
    4.3
    Medium

    CVE-2011-3968

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving Cascading Style Sheets (CSS) token sequences.

    Published: 9 Feb 2012
    5
    Medium

    CVE-2011-3972

    Last Modified: 11 Apr 2025

    The shader translator implementation in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 9 Feb 2012
    5
    Medium

    CVE-2011-3954

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) via vectors that trigger a large amount of database usage.

    Published: 9 Feb 2012
    9.3
    Critical

    CVE-2011-3961

    Last Modified: 11 Apr 2025

    Race condition in Google Chrome before 17.0.963.46 allows remote attackers to execute arbitrary code via vectors that trigger a crash of a utility process.

    Published: 9 Feb 2012
    7.5
    High

    CVE-2011-3966

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to error handling for Cascading Style Sheets (CSS) token-sequence data.

    Published: 9 Feb 2012
    6.8
    Medium

    CVE-2011-3971

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to mousemove events.

    Published: 9 Feb 2012
    7.5
    High

    CVE-2011-3953

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.46 does not prevent monitoring of the clipboard after a paste event, which has unspecified impact and remote attack vectors.

    Published: 9 Feb 2012
    6.8
    Medium

    CVE-2011-3969

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout of SVG documents.

    Published: 9 Feb 2012
    7.5
    High

    CVE-2012-0882

    Last Modified: 11 Apr 2025

    Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VulnDisco Pack Professional 9.17. NOTE: as of 20120224, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. NOTE: due to lack of details, it is not clear whether this issue is a duplicate of CVE-2012-0492 or another CVE.

    Published: 9 Feb 2012
    4.3
    Medium

    CVE-2011-3960

    Last Modified: 11 Apr 2025

    Google Chrome before 17.0.963.46 does not properly decode audio data, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 9 Feb 2012
    4.3
    Medium

    CVE-2011-3970

    Last Modified: 11 Apr 2025

    libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 9 Feb 2012
    6.5
    Medium

    CVE-2011-5078

    Last Modified: 11 Apr 2025

    The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin authentication for unspecified scripts, which allows remote authenticated users to list or delete user accounts, modify passwords, or read log files via HTTP requests, aka Bug IDs 678497 and 678499.

    Published: 8 Feb 2012
    5
    Medium

    CVE-2012-1035

    Last Modified: 11 Apr 2025

    AdaCore Ada Web Services (AWS) before 2.10.2 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

    Published: 8 Feb 2012
    9.3
    Critical

    CVE-2012-0922

    Last Modified: 11 Apr 2025

    rvrender.dll in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via crafted flags in an RMFF file.

    Published: 8 Feb 2012
    9.3
    Critical

    CVE-2012-0923

    Last Modified: 11 Apr 2025

    The RV20 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle the frame size array, which allows remote attackers to execute arbitrary code via a crafted RV20 RealVideo video stream.

    Published: 8 Feb 2012
    9.3
    Critical

    CVE-2012-0924

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via vectors involving a VIDOBJ_START_CODE code in a header within a video stream.

    Published: 8 Feb 2012
    9.3
    Critical

    CVE-2012-0925

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the RV40 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RV40 RealVideo video stream.

    Published: 8 Feb 2012
    9.3
    Critical

    CVE-2012-0926

    Last Modified: 11 Apr 2025

    The RV10 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle height and width values, which allows remote attackers to execute arbitrary code via a crafted RV10 RealVideo video stream.

    Published: 8 Feb 2012
    9.3
    Critical

    CVE-2012-0928

    Last Modified: 11 Apr 2025

    The ATRAC codec in RealNetworks RealPlayer 11.x and 14.x through 14.0.7, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer 12.x before 12.0.0.1703 does not properly decode samples, which allows remote attackers to execute arbitrary code via a crafted ATRAC audio file.

    Published: 8 Feb 2012
    9.3
    Critical

    CVE-2012-0927

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via vectors involving the coded_frame_size value in a RealAudio audio stream.

    Published: 8 Feb 2012
    4.3
    Medium

    CVE-2012-1034

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the admin interface in EPiServer CMS through 6R2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Feb 2012
    5
    Medium

    CVE-2012-1008

    Last Modified: 11 Apr 2025

    OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SIP INVITE message.

    Published: 8 Feb 2012
    6
    Medium

    CVE-2012-1031

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in EPiServer CMS 5 and 6 through 6R2, in certain configurations using Forms Authentication, allows remote authenticated users to obtain WebAdmins access by leveraging Edit Mode privileges, a different vulnerability than CVE-2011-3416 and CVE-2011-3417.

    Published: 8 Feb 2012
    10
    Critical

    CVE-2012-1002

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Published: 8 Feb 2012
    2.1
    Low

    CVE-2012-1004

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script or HTML via the (1) text, (2) FirstName, (3) LastName, (4) OrganisationName, (5) OrganisationUrl, (6) Profession, (7) Country, (8) State, (9) Address, (10) Location, (11) Telephone, (12) VoIP, (13) InstantMessagingIM, (14) Email, (15) HomePage, or (16) Comment parameter. NOTE: some of these details are obtained from third party information.

    Published: 8 Feb 2012
    7.5
    High

    CVE-2011-5076

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in model/comment.class.php in HDWiki 5.0, 5.1, and possibly other versions allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to index.php. NOTE: some of these details are obtained from third party information.

    Published: 8 Feb 2012
    7.5
    High

    CVE-2011-5077

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in attachement.php in HDWiki 5.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in image directory.

    Published: 8 Feb 2012
    7.5
    High

    CVE-2012-1017

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary SQL commands via the (1) ip_addr[0][1], (2) ip_addr[0][2], or (3) ip_addr[0][9] parameters.

    Published: 8 Feb 2012