CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2011-4163

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Database Archiving Software 6.31 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1213.

    Published: 29 Dec 2011
    10
    Critical

    CVE-2011-4164

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Database Archiving Software 6.31 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1214.

    Published: 29 Dec 2011
    10
    Critical

    CVE-2011-4165

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Database Archiving Software 6.31 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1263.

    Published: 29 Dec 2011
    7.5
    High

    CVE-2011-5022

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in search.php in Pligg CMS 1.1.2 allows remote attackers to execute arbitrary SQL commands via the status parameter.

    Published: 29 Dec 2011
    4.3
    Medium

    CVE-2011-5025

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web script or HTML via (1) the tag parameter to editTag.yaws, (2) the index parameter to showOldPage.yaws, (3) the node parameter to allRefsToMe.yaws, or (4) the text parameter to editPage.yaws.

    Published: 29 Dec 2011
    4.3
    Medium

    CVE-2011-5024

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in mmsearch/design in the Mailman/htdig integration patch for Mailman allows remote attackers to inject arbitrary web script or HTML via the config parameter.

    Published: 29 Dec 2011
    4.3
    Medium

    CVE-2011-5023

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the search program, a different vulnerability than CVE-2011-3986.

    Published: 29 Dec 2011
    7.5
    High

    CVE-2011-5021

    Last Modified: 11 Apr 2025

    PHPIDS before 0.7 does not properly implement Regular Expression Denial of Service (ReDoS) filters, which allows remote attackers to bypass rulesets and add PHP sequences to a file via unspecified vectors.

    Published: 29 Dec 2011
    4.3
    Medium

    CVE-2011-5026

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d allows remote attackers to inject arbitrary web script or HTML via the name parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 29 Dec 2011
    4.7
    Medium

    CVE-2012-0045

    Last Modified: 11 Apr 2025

    The em_syscall function in arch/x86/kvm/emulate.c in the KVM implementation in the Linux kernel before 3.2.14 does not properly handle the 0f05 (aka syscall) opcode, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application, as demonstrated by an NASM file.

    Published: 29 Dec 2011
    7.8
    High

    CVE-2011-5034

    Last Modified: 11 Apr 2025

    Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.

    Published: 29 Dec 2011
    5
    Medium

    CVE-2011-4084

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4858. Reason: This candidate is a duplicate of CVE-2011-4858. Notes: All CVE users should reference CVE-2011-4858 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 28 Dec 2011
    5
    Medium

    CVE-2012-2739

    Last Modified: 11 Apr 2025

    Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

    Published: 28 Dec 2011
    5
    Medium

    CVE-2011-4462

    Last Modified: 11 Apr 2025

    Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

    Published: 28 Dec 2011
    5
    Medium

    CVE-2011-4858

    Last Modified: 11 Apr 2025

    Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

    Published: 28 Dec 2011
    5
    Medium

    CVE-2011-5035

    Last Modified: 11 Apr 2025

    Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka Oracle security ticket S0104869.

    Published: 28 Dec 2011
    5
    Medium

    CVE-2012-0839

    Last Modified: 11 Apr 2025

    OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

    Published: 28 Dec 2011
    5
    Medium

    CVE-2012-1150

    Last Modified: 11 Apr 2025

    Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

    Published: 28 Dec 2011
    5.3
    Medium

    CVE-2011-4461

    Last Modified: 11 Apr 2025

    Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

    Published: 28 Dec 2011
    7.8
    High

    CVE-2011-4815

    Last Modified: 11 Apr 2025

    Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

    Published: 28 Dec 2011
    5
    Medium

    CVE-2011-4838

    Last Modified: 11 Apr 2025

    JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

    Published: 28 Dec 2011
    5
    Medium

    CVE-2011-4885

    Last Modified: 11 Apr 2025

    PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

    Published: 28 Dec 2011
    5
    Medium

    CVE-2011-5036

    Last Modified: 11 Apr 2025

    Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

    Published: 28 Dec 2011
    5
    Medium

    CVE-2011-5037

    Last Modified: 11 Apr 2025

    Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, as demonstrated by attacks against Node.js.

    Published: 28 Dec 2011
    5
    Medium

    CVE-2009-5110

    Last Modified: 11 Apr 2025

    dhttpd allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

    Published: 27 Dec 2011
    5
    Medium

    CVE-2009-5111

    Last Modified: 11 Apr 2025

    GoAhead WebServer allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

    Published: 27 Dec 2011
    7.8
    High

    CVE-2011-1393

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the authentication functionality in the server in IBM Lotus Domino 8.x before 8.5.2 FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Notes RPC packet.

    Published: 27 Dec 2011
    9.3
    Critical

    CVE-2011-4783

    Last Modified: 11 Apr 2025

    The IDAPython plugin before 1.5.2.3 in IDA Pro allows user-assisted remote attackers to execute arbitrary code via a crafted IDB file, related to improper handling of certain swig_runtime_data files in the current working directory.

    Published: 27 Dec 2011
    4.3
    Medium

    CVE-2011-3841

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 for WordPress allows remote attackers to inject arbitrary web script or HTML via the uid parameter.

    Published: 27 Dec 2011
    5
    Medium

    CVE-2011-4050

    Last Modified: 11 Apr 2025

    Buffer overflow in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11200 allows remote attackers to cause a denial of service via a crafted packet to TCP port 12401.

    Published: 27 Dec 2011
    7.5
    High

    CVE-2011-4166

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration before 2.6.4 allows remote attackers to create arbitrary files via crafted form data.

    Published: 27 Dec 2011
    7.5
    High

    CVE-2011-4167

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in MPAUploader.dll in HP Managed Printing Administration before 2.6.4 allows remote attackers to execute arbitrary code via a long filename parameter in an uploadfile action to Default.asp.

    Published: 27 Dec 2011
    7.5
    High

    CVE-2011-4168

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in hpmpa/jobDelivery/Default.asp in HP Managed Printing Administration before 2.6.4 allows remote attackers to create arbitrary files via crafted form data.

    Published: 27 Dec 2011
    10
    Critical

    CVE-2011-4536

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in nettransdll.dll in HistorySvr.exe (aka HistoryServer.exe) in WellinTech KingView 6.53 and 65.30.2010.18018 allows remote attackers to execute arbitrary code via a crafted op-code 3 packet.

    Published: 27 Dec 2011
    7.5
    High

    CVE-2011-4537

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11355 and earlier allow remote attackers to execute arbitrary code or cause a denial of service via a crafted packet to TCP port (1) 12397 or (2) 12399.

    Published: 27 Dec 2011
    7.2
    High

    CVE-2011-4784

    Last Modified: 11 Apr 2025

    The NVIDIA Stereoscopic 3D driver before 7.17.12.7565 does not properly handle commands sent to a named pipe, which allows local users to gain privileges via a crafted application.

    Published: 27 Dec 2011
    7.5
    High

    CVE-2011-4169

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Managed Printing Administration before 2.6.4 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

    Published: 27 Dec 2011
    9.3
    Critical

    CVE-2009-5109

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long entry in a .pls file.

    Published: 25 Dec 2011
    9.3
    Critical

    CVE-2010-5081

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code via a long URL in a .pls file.

    Published: 25 Dec 2011
    10
    Critical

    CVE-2011-5001

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attackers to execute arbitrary code via a crafted IPC packet to TCP port 20101.

    Published: 25 Dec 2011
    10
    Critical

    CVE-2011-5002

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in Final Draft 8 before 8.02 allow remote attackers to execute arbitrary code via a .fdx or .fdxt file with long (1) Word, (2) Transition, (3) Location, (4) Extension, (5) SceneIntro, (6) TimeOfDay, and (7) Character elements.

    Published: 25 Dec 2011
    6
    Medium

    CVE-2011-5004

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in models/importcsv.php in the Fabrik (com_fabrik) component before 2.1.1 for Joomla! allows remote authenticated users with Manager privileges to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

    Published: 25 Dec 2011
    7.5
    High

    CVE-2011-5005

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in QuiXplorer 2.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension using the upload action to index.php, then accessing it via a direct request to the file in an unspecified directory.

    Published: 25 Dec 2011
    9.3
    Critical

    CVE-2011-5006

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in QQPlayer 3.2.845 allows remote attackers to execute arbitrary code via a crafted PnSize value in a MOV file.

    Published: 25 Dec 2011
    7.5
    High

    CVE-2011-5008

    Last Modified: 11 Apr 2025

    Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size value in the packet header, which triggers a heap-based buffer overflow.

    Published: 25 Dec 2011
    5
    Medium

    CVE-2011-5009

    Last Modified: 11 Apr 2025

    The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a crafted Content-Length in an HTTP POST or (2) an invalid HTTP request method.

    Published: 25 Dec 2011
    10
    Critical

    CVE-2011-5010

    Last Modified: 11 Apr 2025

    apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters in the PINGADDRESS parameter for a "u" action.

    Published: 25 Dec 2011
    10
    Critical

    CVE-2011-5007

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.

    Published: 25 Dec 2011
    10
    Critical

    CVE-2011-5012

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2.569 and R1 SP1 before, Reflection 2011 R2 before 15.4.1.327, Reflection Windows Client 7.2 SP1 before hotfix 7.2.1186, and Reflection 14.1 SP1 before 14.1.1.206, allows remote FTP servers to execute arbitrary code via a long directory name in a response to a LIST command.

    Published: 25 Dec 2011
    10
    Critical

    CVE-2011-5003

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier allows remote attackers to execute arbitrary code via a long request to TCP port 4659.

    Published: 25 Dec 2011