CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2011-4698

    Last Modified: 11 Apr 2025

    The AndroidAppTools Easy Filter (com.phoneblocker.android) application 1.1 and 1.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and call records via a crafted application.

    Published: 25 Jan 2012
    6.4
    Medium

    CVE-2011-4699

    Last Modified: 11 Apr 2025

    The Ubermedia Twidroyd Legacy (com.twidroydlegacy) application 4.3.11 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4700

    Last Modified: 11 Apr 2025

    The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4701

    Last Modified: 11 Apr 2025

    The CallConfirm (jp.gr.java_conf.ofnhwx.callconfirm) application 2.0.0 for Android does not properly protect data, which allows remote attackers to read or modify allow/block lists via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4704

    Last Modified: 11 Apr 2025

    The Voxofon (com.voxofon) application before 2.5.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS information via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4705

    Last Modified: 11 Apr 2025

    The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attackers to read or modify blacklists and a contact list via a crafted application that launches a "data-flow attack."

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4769

    Last Modified: 11 Apr 2025

    The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4770

    Last Modified: 11 Apr 2025

    The QIWI Wallet (ru.mw) application before 1.14.2 for Android does not properly protect data, which allows remote attackers to read or modify financial information via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4771

    Last Modified: 11 Apr 2025

    The Scan to PDF Free (com.scan.to.pdf.trial) application 2.0.4 for Android does not properly protect data, which allows remote attackers to read or modify scanned files and a Google account via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4773

    Last Modified: 11 Apr 2025

    The AnGuanJia (com.anguanjia.safe) application 2.10.343 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4864

    Last Modified: 11 Apr 2025

    The Tencent MobileQQ (com.tencent.mobileqq) application 2.2 for Android does not properly protect data, which allows remote attackers to read or modify messages and a friends list via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4865

    Last Modified: 11 Apr 2025

    The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attackers to read or modify message drafts and search keywords via a crafted application.

    Published: 25 Jan 2012
    6.4
    Medium

    CVE-2011-4866

    Last Modified: 11 Apr 2025

    The Kaixin001 (com.kaixin001.activity) application 1.3.1 and 1.3.3 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a cleartext password via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4867

    Last Modified: 11 Apr 2025

    The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a password hash via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4703

    Last Modified: 11 Apr 2025

    The Limit My Call (com.limited.call.view) application 2.11 for Android does not properly protect data, which allows remote attackers to read or modify call logs and a contact list via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4863

    Last Modified: 11 Apr 2025

    The Tencent QQPimSecure (com.tencent.qqpimsecure) application 3.0.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS/MMS messages and a contact list via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4702

    Last Modified: 11 Apr 2025

    The Nimbuzz (com.nimbuzz) application 2.0.8 and 2.0.10 for Android does not properly protect data, which allows remote attackers to read or modify a contact list via a crafted application.

    Published: 25 Jan 2012
    5.8
    Medium

    CVE-2011-4772

    Last Modified: 11 Apr 2025

    The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application.

    Published: 25 Jan 2012
    4.9
    Medium

    CVE-2011-4086

    Last Modified: 11 Apr 2025

    The journal_unmap_buffer function in fs/jbd2/transaction.c in the Linux kernel before 3.3.1 does not properly handle the _Delay and _Unwritten buffer head states, which allows local users to cause a denial of service (system crash) by leveraging the presence of an ext4 filesystem that was mounted with a journal.

    Published: 25 Jan 2012
    4.3
    Medium

    CVE-2012-0389

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.53, and 6.x before 6.03 allows remote attackers to inject arbitrary web script or HTML via the Username parameter.

    Published: 24 Jan 2012
    4.3
    Medium

    CVE-2012-0790

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in smokeping_cgi in Smokeping 2.4.2, 2.6.6, and other versions before 2.6.7 allows remote attackers to inject arbitrary web script or HTML via the displaymode parameter.

    Published: 24 Jan 2012
    4.3
    Medium

    CVE-2012-0791

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.

    Published: 24 Jan 2012
    4.3
    Medium

    CVE-2012-0908

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the link_href parameter.

    Published: 24 Jan 2012
    7.5
    High

    CVE-2012-0913

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in checklogin.aspx in ICloudCenter ICTimeAttendance 1.0 allows remote attackers to execute arbitrary SQL commands via the passw parameter. NOTE: Some of these details are obtained from third party information.

    Published: 24 Jan 2012
    4.3
    Medium

    CVE-2012-0914

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in display_renderers/panels_renderer_editor.class.php in the admin view in the Panels module 6.x-2.x before 6.x-3.10 and 7.x-3.x before 7.x-3.0 for Drupal allows remote authenticated users with certain privileges to inject arbitrary web script or HTML via the Region title.

    Published: 24 Jan 2012
    9.3
    Critical

    CVE-2012-0915

    Last Modified: 11 Apr 2025

    Integer signedness error in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via crafted dimensions of a skin file, leading to a heap-based buffer overflow, as demonstrated using a BMP image.

    Published: 24 Jan 2012
    9.3
    Critical

    CVE-2012-0916

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via a crafted image in a chat message, as demonstrated using a PNG file.

    Published: 24 Jan 2012
    4.3
    Medium

    CVE-2012-0917

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Hitachi IT Operations Analyzer 02-01, 02-51 through 02-51-01, and 02-53 through 02-53-02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 24 Jan 2012
    4.3
    Medium

    CVE-2012-0909

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Horde_Form in Horde Groupware Webmail Edition before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to email verification. NOTE: Some of these details are obtained from third party information.

    Published: 24 Jan 2012
    10
    Critical

    CVE-2012-0918

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Hitachi COBOL2002 Net Developer, Net Server Suite, and Net Client Suite 01-00, 01-01 through 01-01-/D, 01-02 through 01-02-/F, 01-03 through 01-03-/F, 02-00 through 02-00-/D, 02-01 through 02-01-/C, and possibly other versions before 02-01-/D allows remote attackers to execute arbitrary code via unknown attack vectors.

    Published: 24 Jan 2012
    4.3
    Medium

    CVE-2012-0040

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.

    Published: 24 Jan 2012
    7.5
    High

    CVE-2012-0069

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ajax.php in Batavi before 1.2.1 allows remote attackers to execute arbitrary SQL commands via the boxToReload parameter.

    Published: 24 Jan 2012
    4.3
    Medium

    CVE-2012-0919

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Hitachi IT Operations Director 02-50-01 through 02-50-07, 03-00 through 03-00-04, and possibly other versions before 03-00-06, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 24 Jan 2012
    4.3
    Medium

    CVE-2012-0285

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork before 6.0.8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 24 Jan 2012
    7.5
    High

    CVE-2012-0912

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 24 Jan 2012
    6.8
    Medium

    CVE-2012-0286

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack the authentication of unspecified victims for requests that modify user accounts.

    Published: 24 Jan 2012
    7.5
    High

    CVE-2011-3924

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOM selections.

    Published: 24 Jan 2012
    7.5
    High

    CVE-2011-3925

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the Safe Browsing feature in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via vectors related to a navigation entry and an interstitial page.

    Published: 24 Jan 2012
    7.5
    High

    CVE-2011-3926

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 24 Jan 2012
    7.5
    High

    CVE-2011-3927

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 16.0.912.77, does not perform all required initialization of values, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 24 Jan 2012
    7.5
    High

    CVE-2011-3928

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOM handling.

    Published: 24 Jan 2012
    4.3
    Medium

    CVE-2012-0313

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in glucose 2 before stage 6.2 allows remote attackers to inject arbitrary web script or HTML via an RSS feed.

    Published: 24 Jan 2012
    7.5
    High

    CVE-2012-0036

    Last Modified: 11 Apr 2025

    curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.

    Published: 24 Jan 2012
    9.3
    Critical

    CVE-2012-0192

    Last Modified: 11 Apr 2025

    Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.

    Published: 23 Jan 2012
    7.4
    High

    CVE-2012-0029

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.

    Published: 23 Jan 2012
    4.3
    Medium

    CVE-2012-0053

    Last Modified: 11 Apr 2025

    protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

    Published: 23 Jan 2012
    9.8
    Critical

    CVE-2011-3923

    Last Modified: 21 Nov 2024

    Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.

    Published: 22 Jan 2012
    5
    Medium

    CVE-2012-0898

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in meb_download.php in the myEASYbackup plugin 1.0.8.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dwn_file parameter.

    Published: 20 Jan 2012
    4.3
    Medium

    CVE-2012-0899

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in referencement/sites_inscription.php in Annuaire PHP allows remote attackers to inject arbitrary web script or HTML via the url parameter and possibly the nom parameter.

    Published: 20 Jan 2012
    4.3
    Medium

    CVE-2012-0901

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.

    Published: 20 Jan 2012