CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2011-4719

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.63 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

    Published: 9 Dec 2011
    5.9
    Medium

    CVE-2011-4600

    Last Modified: 12 Apr 2025

    The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

    Published: 9 Dec 2011
    6.9
    Medium

    CVE-2011-4945

    Last Modified: 11 Apr 2025

    PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentication.

    Published: 9 Dec 2011
    6.8
    Medium

    CVE-2011-4315

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.

    Published: 8 Dec 2011
    7.2
    High

    CVE-2011-0291

    Last Modified: 11 Apr 2025

    The BlackBerry PlayBook service on the Research In Motion (RIM) BlackBerry PlayBook tablet with software before 1.0.8.6067 allows local users to gain privileges via a crafted configuration file in a backup archive.

    Published: 8 Dec 2011
    7.5
    High

    CVE-2011-2917

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the zorder parameter.

    Published: 8 Dec 2011
    4.3
    Medium

    CVE-2011-4707

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Virus Scan Interface in SAP Netweaver allow remote attackers to inject arbitrary web script or HTML via the (1) instname parameter to the VsiTestScan servlet and (2) name parameter to the VsiTestServlet servlet.

    Published: 8 Dec 2011
    4.3
    Medium

    CVE-2011-4708

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational Asset Manager before 7.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Dec 2011
    4.3
    Medium

    CVE-2011-4709

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Hotaru.php in the Search plugin 1.3 for Hotaru CMS allow remote attackers to inject arbitrary web script or HTML via the (1) SITE_NAME parameter to admin_index.php, or the (2) return and (3) search parameters to index.php. NOTE: some of these details are obtained from third party information.

    Published: 8 Dec 2011
    7.5
    High

    CVE-2011-4710

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI.

    Published: 8 Dec 2011
    5
    Medium

    CVE-2011-4713

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the _ID parameter to (1) catalog/shopping_cart.php or (2) catalog/content.php.

    Published: 8 Dec 2011
    5
    Medium

    CVE-2011-4714

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Virtual Vertex Muster before 6.20 allows remote attackers to read arbitrary files via a \.. (backslash dot dot) in the URL.

    Published: 8 Dec 2011
    5
    Medium

    CVE-2011-4716

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read arbitrary files via the file parameter.

    Published: 8 Dec 2011
    5
    Medium

    CVE-2011-4712

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request.

    Published: 8 Dec 2011
    5
    Medium

    CVE-2011-4715

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the KohaOpacLanguage cookie to cgi-bin/opac/opac-main.pl, related to Output.pm.

    Published: 8 Dec 2011
    5
    Medium

    CVE-2011-4711

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in namazu.cgi in Namazu before 2.0.16 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) lang or (2) result parameter.

    Published: 8 Dec 2011
    5
    Medium

    CVE-2011-3179

    Last Modified: 11 Apr 2025

    The server process in Novell Messenger 2.1 and 2.2.x before 2.2.1, and Novell GroupWise Messenger 2.04 and earlier, allows remote attackers to read from arbitrary memory locations via a crafted command.

    Published: 8 Dec 2011
    4.3
    Medium

    CVE-2011-4054

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in login.fcc in CA SiteMinder R6 SP6 before CR7 and R12 SP3 before CR8 allows remote attackers to inject arbitrary web script or HTML via the postpreservationdata parameter.

    Published: 8 Dec 2011
    4.3
    Medium

    CVE-2011-4265

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in phpWebSite before 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Dec 2011
    4.3
    Medium

    CVE-2011-4264

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Etomite before 1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Dec 2011
    10
    Critical

    CVE-2011-2653

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the rtrlet component in Novell ZENworks Asset Management (ZAM) 7.5 allows remote attackers to execute arbitrary code by uploading an executable file.

    Published: 8 Dec 2011
    4.3
    Medium

    CVE-2011-3206

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Dec 2011
    6.8
    Medium

    CVE-2011-4517

    Last Modified: 11 Apr 2025

    The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a JPEG2000 file.

    Published: 8 Dec 2011
    6.8
    Medium

    CVE-2011-4516

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.

    Published: 8 Dec 2011
    3.5
    Low

    CVE-2011-4573

    Last Modified: 12 Apr 2025

    Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote authenticated users when deleting a plug-in configuration update from the group connection properties history, which prevents such activities from being recorded in the audit trail.

    Published: 8 Dec 2011
    6.9
    Medium

    CVE-2011-4695

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Microsoft Windows 7 SP1, when Java is installed, allows local users to bypass Internet Explorer sandbox restrictions and gain privileges via unknown vectors, as demonstrated by the White Phosphorus wp_ie_sandbox_escape module for Immunity CANVAS. NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 7 Dec 2011
    4.3
    Medium

    CVE-2010-5068

    Last Modified: 11 Apr 2025

    The Cascading Style Sheets (CSS) implementation in Opera 10.5 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.

    Published: 7 Dec 2011
    5
    Medium

    CVE-2010-5071

    Last Modified: 11 Apr 2025

    The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.

    Published: 7 Dec 2011
    5
    Medium

    CVE-2010-5072

    Last Modified: 11 Apr 2025

    The JavaScript implementation in Opera 10.5 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.

    Published: 7 Dec 2011
    5
    Medium

    CVE-2010-5073

    Last Modified: 11 Apr 2025

    The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method. NOTE: this may overlap CVE-2010-5070.

    Published: 7 Dec 2011
    4.3
    Medium

    CVE-2011-4680

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the customer portal in vtiger CRM before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Dec 2011
    5
    Medium

    CVE-2011-4681

    Last Modified: 11 Apr 2025

    Opera before 11.60 does not properly consider the number of . (dot) characters that conventionally exist in domain names of different top-level domains, which allows remote attackers to bypass the Same Origin Policy by leveraging access to a different domain name in the same top-level domain, as demonstrated by the .no or .uk domain.

    Published: 7 Dec 2011
    6.4
    Medium

    CVE-2011-4682

    Last Modified: 11 Apr 2025

    The JavaScript engine in Opera before 11.60 does not properly implement the in operator, which allows remote attackers to bypass the Same Origin Policy via vectors related to variables on different web sites.

    Published: 7 Dec 2011
    10
    Critical

    CVE-2011-4683

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.60 has unknown impact and attack vectors, related to a "moderately severe issue."

    Published: 7 Dec 2011
    10
    Critical

    CVE-2011-4684

    Last Modified: 11 Apr 2025

    Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases."

    Published: 7 Dec 2011
    5
    Medium

    CVE-2011-4685

    Last Modified: 11 Apr 2025

    Dragonfly in Opera before 11.60 allows remote attackers to cause a denial of service (application crash) via unspecified content on a web page, as demonstrated by forbes.com.

    Published: 7 Dec 2011
    5
    Medium

    CVE-2011-4686

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Web Workers implementation in Opera before 11.60 allows remote attackers to cause a denial of service (application crash) via unknown vectors.

    Published: 7 Dec 2011
    5
    Medium

    CVE-2011-4690

    Last Modified: 11 Apr 2025

    Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.

    Published: 7 Dec 2011
    5
    Medium

    CVE-2011-4691

    Last Modified: 11 Apr 2025

    Google Chrome 15.0.874.121 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.

    Published: 7 Dec 2011
    5
    Medium

    CVE-2011-4692

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the browser cache via crafted JavaScript code, as demonstrated by visipisi.

    Published: 7 Dec 2011
    4.3
    Medium

    CVE-2002-2435

    Last Modified: 11 Apr 2025

    The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.

    Published: 7 Dec 2011
    5
    Medium

    CVE-2002-2437

    Last Modified: 11 Apr 2025

    The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.

    Published: 7 Dec 2011
    4.3
    Medium

    CVE-2010-5074

    Last Modified: 11 Apr 2025

    The layout engine in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 executes different code for visited and unvisited links during the processing of Cascading Style Sheets (CSS) token sequences, which makes it easier for remote attackers to obtain sensitive information about visited web pages via a timing attack.

    Published: 7 Dec 2011
    4
    Medium

    CVE-2011-4679

    Last Modified: 11 Apr 2025

    vtiger CRM before 5.3.0 does not properly recognize the disabled status of a field in the Leads module, which allows remote authenticated users to bypass intended access restrictions by reading a previously created report.

    Published: 7 Dec 2011
    5
    Medium

    CVE-2011-4689

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.

    Published: 7 Dec 2011
    4.3
    Medium

    CVE-2002-2436

    Last Modified: 11 Apr 2025

    The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.

    Published: 7 Dec 2011
    4.3
    Medium

    CVE-2010-5069

    Last Modified: 11 Apr 2025

    The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document. NOTE: this may overlap CVE-2010-2264.

    Published: 7 Dec 2011
    5
    Medium

    CVE-2010-5070

    Last Modified: 11 Apr 2025

    The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method, a different vulnerability than CVE-2010-2264. NOTE: this may overlap CVE-2010-5073.

    Published: 7 Dec 2011
    4.3
    Medium

    CVE-2011-4263

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Dec 2011
    5
    Medium

    CVE-2011-4687

    Last Modified: 11 Apr 2025

    Opera before 11.60 allows remote attackers to cause a denial of service (CPU and memory consumption) via unspecified content on a web page, as demonstrated by a page under the cisco.com home page.

    Published: 7 Dec 2011