CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2011-4371

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 10 Jan 2012
    9.3
    Critical

    CVE-2012-0001

    Last Modified: 11 Apr 2025

    The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly load structured exception handling tables, which allows context-dependent attackers to bypass the SafeSEH security feature by leveraging a Visual C++ .NET 2003 application, aka "Windows Kernel SafeSEH Bypass Vulnerability."

    Published: 10 Jan 2012
    8.1
    High

    CVE-2012-0003

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote Code Execution Vulnerability."

    Published: 10 Jan 2012
    6.9
    Medium

    CVE-2012-0005

    Last Modified: 11 Apr 2025

    The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean system locale is used, can access uninitialized memory during the processing of Unicode characters, which allows local users to gain privileges via a crafted application, aka "CSRSS Elevation of Privilege Vulnerability."

    Published: 10 Jan 2012
    7.8
    High

    CVE-2011-4785

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the HP-ChaiSOE/1.0 web server on the HP LaserJet P3015 printer with firmware before 07.080.3, LaserJet 4650 printer with firmware 07.006.0, and LaserJet 2430 printer with firmware 08.113.0_I35128 allows remote attackers to read arbitrary files via unspecified vectors, a different vulnerability than CVE-2008-4419.

    Published: 10 Jan 2012
    7.5
    High

    CVE-2012-0207

    Last Modified: 11 Apr 2025

    The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and panic) via IGMP packets.

    Published: 10 Jan 2012
    2.9
    Low

    CVE-2012-0042

    Last Modified: 11 Apr 2025

    Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 does not properly perform certain string conversions, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet, related to epan/to_str.c.

    Published: 10 Jan 2012
    5.8
    Medium

    CVE-2012-0043

    Last Modified: 11 Apr 2025

    Buffer overflow in the reassemble_message function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a series of fragmented RLC packets.

    Published: 10 Jan 2012
    4.3
    Medium

    CVE-2012-0066

    Last Modified: 11 Apr 2025

    Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a (1) Accellent 5Views (aka .5vw) file, (2) I4B trace file, or (3) NETMON 2 capture file.

    Published: 10 Jan 2012
    4.3
    Medium

    CVE-2012-0067

    Last Modified: 11 Apr 2025

    wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in an AIX iptrace file.

    Published: 10 Jan 2012
    4.3
    Medium

    CVE-2012-0068

    Last Modified: 11 Apr 2025

    The lanalyzer_read function in wiretap/lanalyzer.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a Novell capture file containing a record that is too small.

    Published: 10 Jan 2012
    4.9
    Medium

    CVE-2011-4325

    Last Modified: 11 Apr 2025

    The NFS implementation in Linux kernel before 2.6.31-rc6 calls certain functions without properly initializing certain data, which allows local users to cause a denial of service (NULL pointer dereference and O_DIRECT oops), as demonstrated using diotest4 from LTP.

    Published: 10 Jan 2012
    7.1
    High

    CVE-2011-4348

    Last Modified: 11 Apr 2025

    Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets. NOTE: in some environments, this issue exists because of an incomplete fix for CVE-2011-2482.

    Published: 10 Jan 2012
    4.3
    Medium

    CVE-2012-0041

    Last Modified: 11 Apr 2025

    The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a capture file, as demonstrated by an airopeek file.

    Published: 10 Jan 2012
    5
    Medium

    CVE-2012-0781

    Last Modified: 11 Apr 2025

    The tidy_diagnose function in PHP 5.3.8 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that attempts to perform Tidy::diagnose operations on invalid objects, a different vulnerability than CVE-2011-4153.

    Published: 10 Jan 2012
    7.1
    High

    CVE-2012-2100

    Last Modified: 11 Apr 2025

    The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 3.2.2, on the x86 platform and unspecified other platforms, allows user-assisted remote attackers to trigger inconsistent filesystem-groups data and possibly cause a denial of service via a malformed ext4 filesystem containing a super block with a large FLEX_BG group size (aka s_log_groups_per_flex value). NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4307.

    Published: 10 Jan 2012
    4.9
    Medium

    CVE-2012-0059

    Last Modified: 3 Apr 2026

    A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrators can exploit this by reading server logs and emails, leading to the unauthorized disclosure of user passwords.

    Published: 10 Jan 2012
    5
    Medium

    CVE-2011-4153

    Last Modified: 11 Apr 2025

    PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

    Published: 10 Jan 2012
    9.3
    Critical

    CVE-2012-0035

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.

    Published: 9 Jan 2012
    5
    Medium

    CVE-2011-4532

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in Siemens Automation License Manager (ALM) 2.0 through 5.1+SP1+Upd2 allows remote attackers to overwrite arbitrary files via the Save method.

    Published: 8 Jan 2012
    5
    Medium

    CVE-2011-4530

    Last Modified: 11 Apr 2025

    Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote attackers to cause a denial of service (exception and daemon crash) via long fields, as demonstrated by fields to the (1) open_session->workstation->NAME or (2) grant->VERSION function.

    Published: 8 Jan 2012
    5
    Medium

    CVE-2011-4531

    Last Modified: 11 Apr 2025

    Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted content in a (1) get_target_ocx_param or (2) send_target_ocx_param command.

    Published: 8 Jan 2012
    7.5
    High

    CVE-2011-4529

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow remote attackers to execute arbitrary code via a long serialid field in an _licensekey command, as demonstrated by the (1) check_licensekey or (2) read_licensekey command.

    Published: 8 Jan 2012
    5
    Medium

    CVE-2011-4360

    Last Modified: 11 Apr 2025

    MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.

    Published: 8 Jan 2012
    5
    Medium

    CVE-2011-4361

    Last Modified: 11 Apr 2025

    MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.

    Published: 8 Jan 2012
    5
    Medium

    CVE-2011-5055

    Last Modified: 11 Apr 2025

    MaraDNS 1.3.07.12 and 1.4.08 computes hash values for DNS data without properly restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set. NOTE: this issue exists because of an incomplete fix for CVE-2012-0024.

    Published: 8 Jan 2012
    7.8
    High

    CVE-2012-0024

    Last Modified: 11 Apr 2025

    MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set.

    Published: 8 Jan 2012
    5.8
    Medium

    CVE-2011-4056

    Last Modified: 11 Apr 2025

    An unspecified ActiveX control in ActBar.ocx in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to create or overwrite arbitrary files via the save method.

    Published: 8 Jan 2012
    2.1
    Low

    CVE-2011-5056

    Last Modified: 11 Apr 2025

    The authoritative server in MaraDNS through 2.0.04 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which might allow local users to cause a denial of service (CPU consumption) via crafted records in zone files, a different vulnerability than CVE-2012-0024.

    Published: 8 Jan 2012
    5.5
    Medium

    CVE-2012-0058

    Last Modified: 11 Apr 2025

    The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.

    Published: 8 Jan 2012
    9.3
    Critical

    CVE-2011-4055

    Last Modified: 11 Apr 2025

    Buffer overflow in the WebClient ActiveX control in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to execute arbitrary code via a long string in a parameter associated with the location URL.

    Published: 8 Jan 2012
    6.8
    Medium

    CVE-2011-4870

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the (1) GUIControls, (2) BatchObjSrv, and (3) BatchSecCtrl ActiveX controls in Invensys Wonderware InBatch 9.0 and 9.0 SP1, and InBatch 8.1 SP1, 9.0 SP2, and 9.5 Server and Runtime Clients, allow remote attackers to execute arbitrary code via a long string in a property value, a different issue than CVE-2011-3141.

    Published: 8 Jan 2012
    7.5
    High

    CVE-2011-3921

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving animation frames.

    Published: 7 Jan 2012
    6.9
    Medium

    CVE-2011-5054

    Last Modified: 11 Apr 2025

    kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any configured PAM stack, and possibly trigger unintended side effects, via an arbitrary valid PAM service name, a different vulnerability than CVE-2011-4122. NOTE: the vendor indicates that the possibility of resultant privilege escalation may be "a bit far-fetched."

    Published: 6 Jan 2012
    5.8
    Medium

    CVE-2011-5053

    Last Modified: 11 Apr 2025

    The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed PIN authentication, which makes it easier for remote attackers to discover the PIN value, and consequently discover the Wi-Fi network password or reconfigure an access point, by reading EAP-NACK messages.

    Published: 6 Jan 2012
    4.3
    Medium

    CVE-2011-4616

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the HTML-Template-Pro module before 0.9507 for Perl allows remote attackers to inject arbitrary web script or HTML via template parameters, related to improper handling of > (greater than) and < (less than) characters.

    Published: 6 Jan 2012
    2.6
    Low

    CVE-2012-0287

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.

    Published: 6 Jan 2012
    7.5
    High

    CVE-2011-3919

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 6 Jan 2012
    7.5
    High

    CVE-2011-3922

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to glyph handling.

    Published: 6 Jan 2012
    4.3
    Medium

    CVE-2011-5019

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in setup/index.php in Textpattern CMS 4.4.1, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the ddb parameter.

    Published: 5 Jan 2012
    2.3
    Low

    CVE-2012-0833

    Last Modified: 11 Apr 2025

    The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.

    Published: 5 Jan 2012
    4.3
    Medium

    CVE-2012-0390

    Last Modified: 11 Apr 2025

    The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.

    Published: 5 Jan 2012
    5
    Medium

    CVE-2012-0840

    Last Modified: 11 Apr 2025

    tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

    Published: 5 Jan 2012
    4.3
    Medium

    CVE-2007-6751

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the MailForm plugin before 1.20 for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Jan 2012
    4.3
    Medium

    CVE-2011-4920

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.26, and other versions before 1.0.0, allow remote attackers to inject arbitrary web script or HTML via the URL to (1) e107_images/thumb.php or (2) rate.php, (3) resend_name parameter to e107_admin/users.php, and (4) link BBCode in user signatures.

    Published: 4 Jan 2012
    5.1
    Medium

    CVE-2011-4921

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in usersettings.php in e107 0.7.26, and possibly other versions before 1.0.0, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 4 Jan 2012
    4.3
    Medium

    CVE-2011-5049

    Last Modified: 11 Apr 2025

    MySQL 5.5.8, when running on Windows, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted packet to TCP port 3306.

    Published: 4 Jan 2012
    6
    Medium

    CVE-2011-5050

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in corporate/Controller in Elitecore Technologies Cyberoam UTM before 10.01.2 build 059 allows remote authenticated administrators to execute arbitrary SQL commands via the tableid parameter. NOTE: some of these details are obtained from third party information.

    Published: 4 Jan 2012
    6.8
    Medium

    CVE-2011-5052

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in CoCSoft Stream Down 6.8.0 allows remote web servers to execute arbitrary code via a long response to a download request.

    Published: 4 Jan 2012
    7.5
    High

    CVE-2011-5051

    Last Modified: 11 Apr 2025

    Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension using (1) uploadify/upload_admin_avatar.php or (2) uploadify/upload_profile_avatar.php, then accessing it via a direct request to the file in an unspecified directory inside the webroot.

    Published: 4 Jan 2012