CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2012-0026

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0287. Reason: This candidate is a duplicate of CVE-2012-0287. Notes: All CVE users should reference CVE-2012-0287 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 Jan 2012
    4
    Medium

    CVE-2011-1384

    Last Modified: 11 Apr 2025

    The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.

    Published: 4 Jan 2012
    4.3
    Medium

    CVE-2011-1386

    Last Modified: 11 Apr 2025

    IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, and 6.2.1 do not properly handle signature validations based on SAML 1.0, 1.1, and 2.0, which allows remote attackers to bypass intended authentication or authorization requirements via a non-conforming SAML signature.

    Published: 4 Jan 2012
    6.9
    Medium

    CVE-2011-3337

    Last Modified: 11 Apr 2025

    eEye Audit ID 2499 in eEye Digital Security Audits 2406 through 2423 for eEye Retina Network Security Scanner on HP-UX, IRIX, and Solaris allows local users to gain privileges via a Trojan horse gauntlet program in an arbitrary directory under /usr/local/.

    Published: 4 Jan 2012
    4.3
    Medium

    CVE-2011-4108

    Last Modified: 11 Apr 2025

    The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.

    Published: 4 Jan 2012
    9.3
    Critical

    CVE-2011-4109

    Last Modified: 11 Apr 2025

    Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an unspecified impact by triggering failure of a policy check.

    Published: 4 Jan 2012
    4.3
    Medium

    CVE-2011-4577

    Last Modified: 11 Apr 2025

    OpenSSL before 0.9.8s and 1.x before 1.0.0f, when RFC 3779 support is enabled, allows remote attackers to cause a denial of service (assertion failure) via an X.509 certificate containing certificate-extension data associated with (1) IP address blocks or (2) Autonomous System (AS) identifiers.

    Published: 4 Jan 2012
    5
    Medium

    CVE-2011-4619

    Last Modified: 11 Apr 2025

    The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

    Published: 4 Jan 2012
    5
    Medium

    CVE-2012-0027

    Last Modified: 11 Apr 2025

    The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.

    Published: 4 Jan 2012
    5
    Medium

    CVE-2011-4576

    Last Modified: 11 Apr 2025

    The SSL 3.0 implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly initialize data structures for block cipher padding, which might allow remote attackers to obtain sensitive information by decrypting the padding data sent by an SSL peer.

    Published: 4 Jan 2012
    5
    Medium

    CVE-2012-4557

    Last Modified: 11 Apr 2025

    The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.

    Published: 4 Jan 2012
    7.5
    High

    CVE-2011-4197

    Last Modified: 11 Apr 2025

    etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.

    Published: 3 Jan 2012
    4.3
    Medium

    CVE-2011-5047

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in status_rrd_graph.php in pfSense before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the style parameter.

    Published: 3 Jan 2012
    4.3
    Medium

    CVE-2011-5048

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Web Experience Factory (aka WEF, formerly WebSphere Portlet Factory) 7.0 and 7.0.1 allow remote attackers to inject arbitrary web script or HTML via a (1) text INPUT element or (2) TEXTAREA element, related to an interaction between Smart Refresh and Dojo.

    Published: 3 Jan 2012
    4
    Medium

    CVE-2011-4643

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitrary files via a .. (dot dot) in a URI to (1) Splunk Web or (2) the Splunkd HTTP Server, aka SPL-45243.

    Published: 3 Jan 2012
    9.3
    Critical

    CVE-2011-4644

    Last Modified: 11 Apr 2025

    Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does not support authentication, which allows remote attackers to (1) read arbitrary files via a management-console session that leverages the ability to create crafted data sources, or (2) execute management commands via an HTTP request.

    Published: 3 Jan 2012
    4.3
    Medium

    CVE-2011-4778

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 4.2.x before 4.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPL-44614.

    Published: 3 Jan 2012
    4.6
    Medium

    CVE-2011-4642

    Last Modified: 11 Apr 2025

    mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python classes, which allows remote authenticated administrators to execute arbitrary code by leveraging the sys module in a request to the search application, as demonstrated by a cross-site request forgery (CSRF) attack, aka SPL-45172.

    Published: 3 Jan 2012
    4.3
    Medium

    CVE-2011-3657

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when debug mode is used, allow remote attackers to inject arbitrary web script or HTML via vectors involving a (1) tabular report, (2) graphical report, or (3) new chart.

    Published: 2 Jan 2012
    6.8
    Medium

    CVE-2011-3668

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the authentication of arbitrary users for requests that create bug reports.

    Published: 2 Jan 2012
    6.8
    Medium

    CVE-2011-3667

    Last Modified: 11 Apr 2025

    The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle user_can_create_account settings, which allows remote attackers to create user accounts by leveraging a token contained in an e-mail message.

    Published: 2 Jan 2012
    6.8
    Medium

    CVE-2011-3669

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the authentication of arbitrary users for requests that upload attachments.

    Published: 2 Jan 2012
    1.2
    Low

    CVE-2011-4617

    Last Modified: 11 Apr 2025

    virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary files via a symlink attack on a certain file in /tmp/.

    Published: 31 Dec 2011
    7.5
    High

    CVE-2011-1710

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the HTTP server in the Novell XTier framework 3.1.8 allow remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via crafted header length variables.

    Published: 31 Dec 2011
    9.3
    Critical

    CVE-2011-4620

    Last Modified: 11 Apr 2025

    Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote attackers to execute arbitrary code via vectors involving a long error message, as demonstrated by a crafted acc file for TORCS. NOTE: some of these details are obtained from third party information.

    Published: 31 Dec 2011
    5
    Medium

    CVE-2013-7345

    Last Modified: 12 Apr 2025

    The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.

    Published: 31 Dec 2011
    4.3
    Medium

    CVE-2011-5040

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitrary web script or HTML via the config parameter to (1) nalozi_naslov.php and (2) widget.dokumenti_lista.php.

    Published: 30 Dec 2011
    4.3
    Medium

    CVE-2011-5041

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) d parameter in a blocks action and (2) post_id parameter in an edit-post action to index.php.

    Published: 30 Dec 2011
    4.3
    Medium

    CVE-2011-5042

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in inc/lib/lib.base.php in SASHA 0.2.0 allows remote attackers to inject arbitrary web script or HTML via the instructors parameter. NOTE: the original disclosure also mentions the section_title parameter, but this was disputed by the vendor and retracted by the original researcher.

    Published: 30 Dec 2011
    4.3
    Medium

    CVE-2011-5043

    Last Modified: 11 Apr 2025

    TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a buffer overflow.

    Published: 30 Dec 2011
    4.3
    Medium

    CVE-2011-5045

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inject arbitrary web script or HTML via the page_info_message parameter.

    Published: 30 Dec 2011
    7.5
    High

    CVE-2011-5038

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in hitCode hitAppoint 4.5.17 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Dec 2011
    7.5
    High

    CVE-2011-5039

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to login.php, (3) the filter parameter to widget.dokumenti_lista.php, and (4) the fin_nalog_id parameter to nalozi_naslov.php.

    Published: 30 Dec 2011
    9.3
    Critical

    CVE-2011-5046

    Last Modified: 11 Apr 2025

    The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."

    Published: 30 Dec 2011
    7.2
    High

    CVE-2011-5044

    Last Modified: 11 Apr 2025

    SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute arbitrary code by replacing Diagnose.exe with a Trojan horse program.

    Published: 30 Dec 2011
    8.5
    High

    CVE-2011-3416

    Last Modified: 11 Apr 2025

    The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms Authentication Bypass Vulnerability."

    Published: 30 Dec 2011
    9.3
    Critical

    CVE-2011-3417

    Last Modified: 11 Apr 2025

    The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrary user accounts via a crafted URL, aka "ASP.NET Forms Authentication Ticket Caching Vulnerability."

    Published: 30 Dec 2011
    6.8
    Medium

    CVE-2011-3415

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted return URL, aka "Insecure Redirect in .NET Form Authentication Vulnerability."

    Published: 30 Dec 2011
    7.8
    High

    CVE-2011-3414

    Last Modified: 11 Apr 2025

    The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."

    Published: 30 Dec 2011
    5
    Medium

    CVE-2011-5245

    Last Modified: 11 Apr 2025

    The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.

    Published: 30 Dec 2011
    2.1
    Low

    CVE-2012-0034

    Last Modified: 11 Apr 2025

    The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local users to obtain sensitive information by reading the log file.

    Published: 30 Dec 2011
    5
    Medium

    CVE-2012-0818

    Last Modified: 11 Apr 2025

    RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity (XXE) injection attack.

    Published: 30 Dec 2011
    4.3
    Medium

    CVE-2011-4615

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Zabbix before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the gname parameter (aka host groups name) to (1) hostgroups.php and (2) usergrps.php, the update action to (3) hosts.php and (4) scripts.php, and (5) maintenance.php.

    Published: 29 Dec 2011
    4.3
    Medium

    CVE-2011-5027

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ZABBIX before 1.8.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the profiler.

    Published: 29 Dec 2011
    4
    Medium

    CVE-2011-5028

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in novelllogmanager/FileDownload in Novell Sentinel Log Manager 1.2.0.1_938 and earlier, as used in Novell Sentinel before 7.0.1.0, allows remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 29 Dec 2011
    4.3
    Medium

    CVE-2011-5029

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.7.0 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry parameter to delete.php or (2) category parameter to index.php.

    Published: 29 Dec 2011
    4.9
    Medium

    CVE-2011-5032

    Last Modified: 11 Apr 2025

    WMDrive.sys 3.4.181.224 in WinMount 3.5.1018 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted 0x87342000 IOCTL request to the WMDriver device.

    Published: 29 Dec 2011
    4.4
    Medium

    CVE-2011-5033

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmin server, allows local users to cause a denial of service (crash) via a long string in an admin.list file.

    Published: 29 Dec 2011
    7.5
    High

    CVE-2011-5031

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in servlet/capexweb.parentvalidatepassword in cApexWEB 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) dfuserid and (2) dfpassword parameters. NOTE: some of these details are obtained from third party information.

    Published: 29 Dec 2011
    3.5
    Low

    CVE-2011-5030

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Meta tags quick module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors, probably related to "names of entity bundles."

    Published: 29 Dec 2011