CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2011-4753

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by domains/sitebuilder_edit.php and certain other files.

    Published: 16 Dec 2011
    10
    Critical

    CVE-2011-4755

    Last Modified: 11 Apr 2025

    Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted cookie, as demonstrated by cookies to client@1/domain@1/hosting/file-manager/ and certain other files.

    Published: 16 Dec 2011
    5
    Medium

    CVE-2011-4759

    Last Modified: 11 Apr 2025

    Parallels Plesk Small Business Panel 10.2.0 generates web pages containing external links in response to GET requests with query strings for client@1/domain@1/hosting/file-manager/ and certain other files, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue.

    Published: 16 Dec 2011
    4.3
    Medium

    CVE-2011-4765

    Last Modified: 11 Apr 2025

    The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by Wizard/Edit/Modules/ImageGallery/MultiImagesUpload and certain other files.

    Published: 16 Dec 2011
    7.5
    High

    CVE-2011-4847

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execute arbitrary SQL commands via a certificateslist cookie to notification@/.

    Published: 16 Dec 2011
    4.3
    Medium

    CVE-2011-4848

    Last Modified: 11 Apr 2025

    The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling in certain files under client@1/domain@1/backup/local-repository/.

    Published: 16 Dec 2011
    9.3
    Critical

    CVE-2011-4854

    Last Modified: 11 Apr 2025

    The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Content-Type data in HTML META elements, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving the get_enabled_product_icon program. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.

    Published: 16 Dec 2011
    9.3
    Critical

    CVE-2011-4856

    Last Modified: 11 Apr 2025

    The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/health/parameters and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.

    Published: 16 Dec 2011
    10
    Critical

    CVE-2011-4369

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.

    Published: 16 Dec 2011
    5.5
    Medium

    CVE-2012-0038

    Last Modified: 11 Apr 2025

    Integer overflow in the xfs_acl_from_disk function in fs/xfs/xfs_acl.c in the Linux kernel before 3.1.9 allows local users to cause a denial of service (panic) via a filesystem with a malformed ACL, leading to a heap-based buffer overflow.

    Published: 16 Dec 2011
    6.8
    Medium

    CVE-2011-4837

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authentication of admins for requests that execute arbitrary programs.

    Published: 15 Dec 2011
    Unknown

    CVE-2010-1680

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2010. Notes: none

    Published: 15 Dec 2011
    4.3
    Medium

    CVE-2011-4598

    Last Modified: 11 Apr 2025

    The handle_request_info function in channels/chan_sip.c in Asterisk Open Source 1.6.2.x before 1.6.2.21 and 1.8.x before 1.8.7.2, when automon is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted sequence of SIP requests.

    Published: 15 Dec 2011
    3.6
    Low

    CVE-2011-4606

    Last Modified: 11 Apr 2025

    Artsoft Entertainment Rocks'n'Diamonds (aka rocksndiamonds) 3.3.0.1 allows local users to overwrite arbitrary files via a symlink attack on .rocksndiamonds/cache/artworkinfo.cache under a user's home directory.

    Published: 15 Dec 2011
    7.5
    High

    CVE-2011-4823

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php.

    Published: 15 Dec 2011
    7.5
    High

    CVE-2011-4824

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows remote attackers to execute arbitrary SQL commands via the login_username parameter.

    Published: 15 Dec 2011
    7.5
    High

    CVE-2011-4825

    Last Modified: 11 Apr 2025

    Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.

    Published: 15 Dec 2011
    6.8
    Medium

    CVE-2011-4826

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in session.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to process.php. NOTE: some of these details are obtained from third party information.

    Published: 15 Dec 2011
    4.3
    Medium

    CVE-2011-4827

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in AutoSec Tools V-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) p parameter to redirect.php and (2) box parameter to includes/TrueColorPicker/index.php, which is not properly handled in includes/TrueColorPicker/class.TrueColorPicker.php.

    Published: 15 Dec 2011
    7.5
    High

    CVE-2011-4828

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in temp/.

    Published: 15 Dec 2011
    4
    Medium

    CVE-2011-4831

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to read arbitrary files via a ..%2f (encoded dot dot) in the file parameter in a download action.

    Published: 15 Dec 2011
    7.5
    High

    CVE-2011-4832

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter in a template action.

    Published: 15 Dec 2011
    7.5
    High

    CVE-2011-4833

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0beta1 allow remote attackers to execute arbitrary SQL commands via the (1) where and (2) order parameters in a get_full_list action to index.php.

    Published: 15 Dec 2011
    4.6
    Medium

    CVE-2011-4834

    Last Modified: 11 Apr 2025

    The GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-UX, and Solaris allows local users to gain privileges via (1) a Trojan horse /tmp/tmp.txt FIFO or (2) a symlink attack on /tmp/tmp.txt.

    Published: 15 Dec 2011
    7.5
    High

    CVE-2011-4835

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to access arbitrary files via unspecified vectors.

    Published: 15 Dec 2011
    4.3
    Medium

    CVE-2011-4836

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to inject arbitrary web script or HTML via a request for a crafted URI.

    Published: 15 Dec 2011
    5
    Medium

    CVE-2011-4597

    Last Modified: 11 Apr 2025

    The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses different port numbers for responses to invalid requests depending on whether a SIP username exists, which allows remote attackers to enumerate usernames via a series of requests.

    Published: 15 Dec 2011
    4.3
    Medium

    CVE-2011-4822

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the user profile feature in Atlassian FishEye before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via (1) snippets in a user comment, which is not properly handled in a Confluence page, or (2) the user profile display name, which is not properly handled in a FishEye page.

    Published: 15 Dec 2011
    3.5
    Low

    CVE-2011-4830

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the com_listing component in Barter Sites component 1.3 for Joomla! allow remote authenticated users to inject arbitrary web script or HTML via the (1) listing_title, (2) description, (3) homeurl (aka Website Address), (4) paystring (aka Payment types accepted), (5) sell_price, (6) shipping_cost, and (7) quantity parameters to index.php.

    Published: 15 Dec 2011
    7.5
    High

    CVE-2011-4829

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the com_listing component in Barter Sites component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter to index.php.

    Published: 15 Dec 2011
    4.6
    Medium

    CVE-2011-4613

    Last Modified: 11 Apr 2025

    The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misinterpreted as the console TTY.

    Published: 15 Dec 2011
    4.3
    Medium

    CVE-2011-2463

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the cfform tag.

    Published: 14 Dec 2011
    6.8
    Medium

    CVE-2011-2742

    Last Modified: 11 Apr 2025

    EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly perform forensic evaluation upon receipt of device tokens from mobile apps, which might allow remote attackers to bypass intended application restrictions via a mobile device.

    Published: 14 Dec 2011
    4.3
    Medium

    CVE-2011-4368

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Remote Development Services (RDS) in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Dec 2011
    6.8
    Medium

    CVE-2011-2741

    Last Modified: 11 Apr 2025

    EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly implement Device Recovery and Device Identification, which might allow remote attackers to bypass intended security restrictions on a (1) previously non-registered device or (2) registered device by sending unspecified "data elements."

    Published: 14 Dec 2011
    9.3
    Critical

    CVE-2011-1983

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Office for Mac 2011 allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Use After Free Vulnerability."

    Published: 14 Dec 2011
    4.3
    Medium

    CVE-2011-1992

    Last Modified: 11 Apr 2025

    The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to read content from a different (1) domain or (2) zone via a "trial and error" attack, aka "XSS Filter Information Disclosure Vulnerability."

    Published: 14 Dec 2011
    9.3
    Critical

    CVE-2011-2019

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."

    Published: 14 Dec 2011
    5.8
    Medium

    CVE-2011-2941

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the initialURI parameter.

    Published: 14 Dec 2011
    9.3
    Critical

    CVE-2011-3396

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft PowerPoint 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "PowerPoint Insecure Library Loading Vulnerability."

    Published: 14 Dec 2011
    9.3
    Critical

    CVE-2011-3400

    Last Modified: 11 Apr 2025

    Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability."

    Published: 14 Dec 2011
    9.3
    Critical

    CVE-2011-3401

    Last Modified: 11 Apr 2025

    ENCDEC.DLL in Windows Media Player and Media Center in Microsoft Windows XP SP2 and SP3, Windows Vista SP2, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted .dvr-ms file, aka "Windows Media Player DVR-MS Memory Corruption Vulnerability."

    Published: 14 Dec 2011
    9.3
    Critical

    CVE-2011-3403

    Last Modified: 11 Apr 2025

    Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet, aka "Record Memory Corruption Vulnerability."

    Published: 14 Dec 2011
    4.3
    Medium

    CVE-2011-3404

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not properly use the Content-Disposition HTTP header to control rendering of the HTTP response body, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Content-Disposition Information Disclosure Vulnerability."

    Published: 14 Dec 2011
    9.3
    Critical

    CVE-2011-3410

    Last Modified: 11 Apr 2025

    Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Out-of-bounds Array Index Vulnerability."

    Published: 14 Dec 2011
    9.3
    Critical

    CVE-2011-3411

    Last Modified: 11 Apr 2025

    Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Invalid Pointer Vulnerability."

    Published: 14 Dec 2011
    9.3
    Critical

    CVE-2011-3412

    Last Modified: 11 Apr 2025

    Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect memory handling, aka "Publisher Memory Corruption Vulnerability."

    Published: 14 Dec 2011
    7.5
    High

    CVE-2011-4803

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 14 Dec 2011
    5
    Medium

    CVE-2011-4804

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 14 Dec 2011
    4.3
    Medium

    CVE-2011-4805

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in pubDBLogon.jsp in SAP Crystal Report Server 2008 allows remote attackers to inject arbitrary web script or HTML via the service parameter.

    Published: 14 Dec 2011