CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2011-4191

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a denial of service (abend or NFS outage) via long packets.

    Published: 30 Nov 2011
    2.6
    Low

    CVE-2011-4345

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Namazu before 2.0.21, when Internet Explorer 6 or 7 is used, allows remote attackers to inject arbitrary web script or HTML via a cookie.

    Published: 30 Nov 2011
    7.5
    High

    CVE-2011-4542

    Last Modified: 11 Apr 2025

    Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox Drafts action to the default URI.

    Published: 30 Nov 2011
    7.5
    High

    CVE-2011-3173

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the GetDriverSettings function in nipplib.dll in the iPrint client in Novell Open Enterprise Server 2 (aka OES2) SP3 allows remote attackers to execute arbitrary code via a long (1) hostname or (2) port field.

    Published: 30 Nov 2011
    1.9
    Low

    CVE-2011-4944

    Last Modified: 11 Apr 2025

    Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

    Published: 30 Nov 2011
    6.8
    Medium

    CVE-2011-3150

    Last Modified: 11 Apr 2025

    Software Center in Ubuntu 11.10, 11.04 10.10 does not properly validate server certificates, which allows remote attackers to execute arbitrary code or obtain sensitive information via a man-in-the-middle (MITM) attack.

    Published: 29 Nov 2011
    5
    Medium

    CVE-2011-3367

    Last Modified: 11 Apr 2025

    Arora, possibly 0.11 and other versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.

    Published: 29 Nov 2011
    4.3
    Medium

    CVE-2011-3366

    Last Modified: 11 Apr 2025

    Rekonq 0.7.0 and earlier does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.

    Published: 29 Nov 2011
    7.5
    High

    CVE-2011-4569

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary SQL commands via the image2 parameter.

    Published: 29 Nov 2011
    7.5
    High

    CVE-2011-4570

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Time Returns (com_timereturns) component 2.0 and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a timereturns action to index.php.

    Published: 29 Nov 2011
    7.5
    High

    CVE-2011-4571

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Estate Agent (com_estateagent) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showEO action to index.php.

    Published: 29 Nov 2011
    4.3
    Medium

    CVE-2011-4568

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in view/frontend-head.php in the Flowplayer plugin before 1.2.12 for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI.

    Published: 29 Nov 2011
    4.3
    Medium

    CVE-2011-4572

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this was originally reported as a file disclosure vulnerability, but this is likely inaccurate.

    Published: 29 Nov 2011
    4.3
    Medium

    CVE-2011-4541

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in Hastymail2 2.1.1 before RC2 allows remote attackers to inject arbitrary web script or HTML via the rs parameter in a mailbox Drafts action.

    Published: 29 Nov 2011
    4.3
    Medium

    CVE-2011-4567

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in includes/templates/template_default/templates/tpl_gv_send_default.php in Zen Cart before 1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a gv_send action to index.php, a different vulnerability than CVE-2011-4547.

    Published: 29 Nov 2011
    4.3
    Medium

    CVE-2011-4547

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in includes/templates/template_default/common/tpl_header_test_info.php in Zen Cart 1.3.9h, when debugging is enabled, might allow remote attackers to inject arbitrary web script or HTML via the (1) main_page parameter or (2) PATH_INFO, a different vulnerability than CVE-2011-4567.

    Published: 29 Nov 2011
    7.5
    High

    CVE-2011-4559

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php.

    Published: 28 Nov 2011
    3.5
    Low

    CVE-2011-4560

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Petition Node module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to signing a petition.

    Published: 28 Nov 2011
    4.3
    Medium

    CVE-2011-4561

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php. NOTE: some of these details are obtained from third party information.

    Published: 28 Nov 2011
    4.3
    Medium

    CVE-2011-4562

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in (1) view/admin/log_item.php and (2) view/admin/log_item_details.php in the Redirection plugin 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Referer HTTP header in a request to a post that does not exist.

    Published: 28 Nov 2011
    4.3
    Medium

    CVE-2011-4563

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in JAKCMS 2.0.4.1, and possibly other versions before 2.2.6 2011-09-23, allows remote attackers to inject arbitrary web script or HTML via the userpost parameter in a PM request, related to tinymce. NOTE: some of these details are obtained from third party information.

    Published: 28 Nov 2011
    4.3
    Medium

    CVE-2011-4565

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to include/formdhtmltextarea_preview.php or (2) img BBCODE tag within the message parameter to pmlite.php (aka Private Message). NOTE: some of these details are obtained from third party information.

    Published: 28 Nov 2011
    4.3
    Medium

    CVE-2011-4564

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the admin script in Active CMS 1.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter in a module action.

    Published: 28 Nov 2011
    6.8
    Medium

    CVE-2011-1372

    Last Modified: 11 Apr 2025

    The Web User Interface on the IBM TS3100 and TS3200 tape libraries with firmware before A.60 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.

    Published: 28 Nov 2011
    4.3
    Medium

    CVE-2011-4329

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter in a setup action to admin/company.php, or the PATH_INFO to (2) admin/security_other.php, (3) admin/events.php, or (4) admin/user.php.

    Published: 28 Nov 2011
    4.3
    Medium

    CVE-2011-4335

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php in a (1) teachers.html or (2) teachers/ action.

    Published: 28 Nov 2011
    6.8
    Medium

    CVE-2011-4111

    Last Modified: 12 Apr 2025

    Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.

    Published: 28 Nov 2011
    2.6
    Low

    CVE-2012-0021

    Last Modified: 11 Apr 2025

    The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.

    Published: 28 Nov 2011
    1.9
    Low

    CVE-2011-1378

    Last Modified: 11 Apr 2025

    IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.

    Published: 26 Nov 2011
    9.3
    Critical

    CVE-2011-3828

    Last Modified: 11 Apr 2025

    DVRemoteAx.ax 2.1.0.39 in the DVR Remote ActiveX control allows remote attackers to execute arbitrary code via a crafted DVRobot.dll file in a manifest directory on a web server.

    Published: 26 Nov 2011
    4.3
    Medium

    CVE-2011-4275

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted company name, (2) a crafted database server name, (3) a crafted CSV file, (4) a crafted copy-and-paste action, (5) the auth_user parameter in a suggest_pwd action to UI.php, (6) the c[menu] parameter to UniversalSearch.php, (7) the description parameter in a SearchFormToAdd_document_list action to UI.php, (8) the category parameter in an errors action to audit.php, or (9) the suggest_pwd parameter to UI.php.

    Published: 26 Nov 2011
    10
    Critical

    CVE-2011-4254

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted RTSP SETUP request.

    Published: 24 Nov 2011
    10
    Critical

    CVE-2011-4246

    Last Modified: 11 Apr 2025

    The AAC codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 24 Nov 2011
    9.3
    Critical

    CVE-2011-4247

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted QCELP stream.

    Published: 24 Nov 2011
    9.3
    Critical

    CVE-2011-4248

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a malformed AAC file.

    Published: 24 Nov 2011
    10
    Critical

    CVE-2011-4249

    Last Modified: 11 Apr 2025

    Array index error in the RV30 codec in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 24 Nov 2011
    10
    Critical

    CVE-2011-4250

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the ATRC codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 24 Nov 2011
    9.3
    Critical

    CVE-2011-4251

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted sample size in a RealAudio file.

    Published: 24 Nov 2011
    9.3
    Critical

    CVE-2011-4252

    Last Modified: 11 Apr 2025

    The RV10 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via a crafted sample height.

    Published: 24 Nov 2011
    10
    Critical

    CVE-2011-4256

    Last Modified: 11 Apr 2025

    The RV30 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 does not initialize an unspecified index value, which allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 24 Nov 2011
    9.3
    Critical

    CVE-2011-4257

    Last Modified: 11 Apr 2025

    The Cook codec in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via crafted channel data.

    Published: 24 Nov 2011
    9.3
    Critical

    CVE-2011-4258

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted length of an MLTI chunk in an IVR file.

    Published: 24 Nov 2011
    9.3
    Critical

    CVE-2011-4259

    Last Modified: 11 Apr 2025

    Integer underflow in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted width value in an MPG file.

    Published: 24 Nov 2011
    9.3
    Critical

    CVE-2011-4260

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a malformed header in an MP4 file.

    Published: 24 Nov 2011
    9.3
    Critical

    CVE-2011-4261

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted video dimensions in an MP4 file.

    Published: 24 Nov 2011
    9.3
    Critical

    CVE-2011-4262

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted MP4 file.

    Published: 24 Nov 2011
    10
    Critical

    CVE-2011-4245

    Last Modified: 11 Apr 2025

    The RealVideo renderer in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 24 Nov 2011
    10
    Critical

    CVE-2011-4255

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via an invalid codec name.

    Published: 24 Nov 2011
    10
    Critical

    CVE-2011-4244

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the RealVideo renderer in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 24 Nov 2011
    10
    Critical

    CVE-2011-4253

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the RV20 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 24 Nov 2011