CVE Feed

    Dashboard / CVE

    3.2
    Low

    CVE-2011-4160

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Operations Agent 11.00 and Performance Agent 4.73 and 5.0 on AIX, HP-UX, Linux, and Solaris allows local users to bypass intended directory-access restrictions via unknown vectors.

    Published: 24 Nov 2011
    4.3
    Medium

    CVE-2011-4312

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the commenting system in Review Board before 1.5.7 and 1.6.x before 1.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) diff viewer or (2) screenshot component.

    Published: 24 Nov 2011
    10
    Critical

    CVE-2011-4548

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.44 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

    Published: 24 Nov 2011
    5.8
    Medium

    CVE-2011-4354

    Last Modified: 11 Apr 2025

    crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.

    Published: 24 Nov 2011
    4.3
    Medium

    CVE-2011-4332

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.6.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 Nov 2011
    5
    Medium

    CVE-2011-4321

    Last Modified: 11 Apr 2025

    The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which makes it easier for remote attackers to change the passwords of arbitrary users via unspecified vectors.

    Published: 23 Nov 2011
    Unknown

    CVE-2011-2708

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-2710. Reason: This candidate is a duplicate of CVE-2011-2710. Notes: All CVE users should reference CVE-2011-2710 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Nov 2011
    Unknown

    CVE-2011-4331

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4110. Reason: This candidate is a duplicate of CVE-2011-4110. Notes: All CVE users should reference CVE-2011-4110 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Nov 2011
    4.3
    Medium

    CVE-2010-5046

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin.php in ecoCMS allows remote attackers to inject arbitrary web script or HTML via the p parameter.

    Published: 23 Nov 2011
    7.5
    High

    CVE-2010-5049

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in events.php in Zabbix 1.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the nav_time parameter.

    Published: 23 Nov 2011
    4.3
    Medium

    CVE-2010-5051

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/core/admin_func.php in razorCMS 1.0 stable allows remote attackers to inject arbitrary web script or HTML via the content parameter in an edit action to admin/index.php.

    Published: 23 Nov 2011
    4.3
    Medium

    CVE-2010-5052

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/components.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the val[] parameter.

    Published: 23 Nov 2011
    4.3
    Medium

    CVE-2010-5054

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Special:Login in JAMWiki before 0.8.4 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 23 Nov 2011
    7.5
    High

    CVE-2010-5055

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Almnzm 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Nov 2011
    7.5
    High

    CVE-2010-5056

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the GBU Facebook (com_gbufacebook) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the face_id parameter in a show_face action to index.php.

    Published: 23 Nov 2011
    7.5
    High

    CVE-2010-5057

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the tipodoc_id parameter.

    Published: 23 Nov 2011
    7.5
    High

    CVE-2010-5058

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL commands via the res_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Nov 2011
    7.5
    High

    CVE-2010-5059

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in CMScout 2.0.8 allows remote attackers to execute arbitrary SQL commands via the album parameter in a photos action.

    Published: 23 Nov 2011
    7.5
    High

    CVE-2010-5060

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Nov 2011
    7.5
    High

    CVE-2010-5062

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in search.php in MH Products kleinanzeigenmarkt allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Published: 23 Nov 2011
    7.5
    High

    CVE-2010-5047

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Nov 2011
    4.3
    Medium

    CVE-2010-5048

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php.

    Published: 23 Nov 2011
    4.3
    Medium

    CVE-2010-5050

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in jsp/admin/tools/remote_share.jsp in ManageEngine ADManager Plus 4.4.0 allows remote attackers to inject arbitrary web script or HTML via the computerName parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Nov 2011
    7.5
    High

    CVE-2010-5053

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a prod_desc action to index.php.

    Published: 23 Nov 2011
    7.5
    High

    CVE-2010-5061

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in RSStatic allows remote attackers to execute arbitrary SQL commands via the maxarticles parameter.

    Published: 23 Nov 2011
    4.3
    Medium

    CVE-2011-4317

    Last Modified: 11 Apr 2025

    The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.

    Published: 23 Nov 2011
    6.8
    Medium

    CVE-2011-4718

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID.

    Published: 23 Nov 2011
    7.8
    High

    CVE-2012-0044

    Last Modified: 11 Apr 2025

    Integer overflow in the drm_mode_dirtyfb_ioctl function in drivers/gpu/drm/drm_crtc.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.1.5 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted ioctl call.

    Published: 23 Nov 2011
    7.5
    High

    CVE-2011-4505

    Last Modified: 11 Apr 2025

    The UPnP IGD implementation on SpeedTouch 5x6 devices with firmware before 6.2.29 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.

    Published: 22 Nov 2011
    7.5
    High

    CVE-2011-4506

    Last Modified: 11 Apr 2025

    The UPnP IGD implementation on the Thomson (aka Technicolor) TG585 with firmware 7.x before 7.4.3.2 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.

    Published: 22 Nov 2011
    7.5
    High

    CVE-2011-4500

    Last Modified: 11 Apr 2025

    The UPnP IGD implementation on the Cisco Linksys WRT54GX with firmware 2.00.05, when UPnP is enabled, configures the SOAP server to listen on the WAN port, which allows remote attackers to administer the firewall via SOAP requests.

    Published: 22 Nov 2011
    7.5
    High

    CVE-2011-4507

    Last Modified: 11 Apr 2025

    The D-Link DIR-685 router, when certain WPA and WPA2 configurations are used, does not maintain an encrypted wireless network during transfer of a large amount of network traffic, which allows remote attackers to obtain sensitive information or bypass authentication via a Wi-Fi device.

    Published: 22 Nov 2011
    10
    Critical

    CVE-2011-4502

    Last Modified: 11 Apr 2025

    The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.

    Published: 22 Nov 2011
    7.5
    High

    CVE-2011-4504

    Last Modified: 11 Apr 2025

    The UPnP IGD implementation in the Pseudo ICS UPnP software on the ZyXEL P-330W allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.

    Published: 22 Nov 2011
    7.5
    High

    CVE-2011-4499

    Last Modified: 11 Apr 2025

    The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware before 4.71.1, and WRT54GS v4 with firmware before 1.06.1 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.

    Published: 22 Nov 2011
    10
    Critical

    CVE-2011-4501

    Last Modified: 11 Apr 2025

    The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.

    Published: 22 Nov 2011
    7.5
    High

    CVE-2011-4503

    Last Modified: 11 Apr 2025

    The UPnP IGD implementation in Broadcom Linux on the Sitecom WL-111 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.

    Published: 22 Nov 2011
    7.5
    High

    CVE-2011-4343

    Last Modified: 20 Apr 2025

    Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.

    Published: 22 Nov 2011
    10
    Critical

    CVE-2011-4040

    Last Modified: 11 Apr 2025

    Buffer overflow in MiniSmtp 3.0.11818 in NJStar Communicator allows remote attackers to execute arbitrary code via a crafted packet.

    Published: 21 Nov 2011
    9.3
    Critical

    CVE-2011-4496

    Last Modified: 11 Apr 2025

    Buffer overflow in Aviosoft DTV Player 1.0.1.2 allows remote attackers to execute arbitrary code via a crafted .plf (aka playlist) file.

    Published: 21 Nov 2011
    3.3
    Low

    CVE-2011-4497

    Last Modified: 11 Apr 2025

    QIS_wizard.htm on the ASUS RT-N56U router with firmware before 1.0.1.4o allows remote attackers to obtain the administrator password via a flag=detect request.

    Published: 21 Nov 2011
    6.8
    Medium

    CVE-2011-4498

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web console in Zenprise Device Manager 6.x through 6.1.8 allows remote attackers to hijack the authentication of administrators for requests that wipe mobile devices.

    Published: 21 Nov 2011
    4
    Medium

    CVE-2011-4347

    Last Modified: 11 Apr 2025

    The kvm_vm_ioctl_assign_device function in virt/kvm/assigned-dev.c in the KVM subsystem in the Linux kernel before 3.1.10 does not verify permission to access PCI configuration space and BAR resources, which allows host OS users to assign PCI devices and cause a denial of service (host OS crash) via a KVM_ASSIGN_PCI_DEVICE operation.

    Published: 20 Nov 2011
    5
    Medium

    CVE-2011-3849

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in dxserver before 6279 in CA Directory 8.1 and CA Directory r12 before SP7 CR1 allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP packet.

    Published: 19 Nov 2011
    6.8
    Medium

    CVE-2011-4159

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in System Administration Manager (SAM) in EMS before A.04.20.11.04_01 on HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges via unknown vectors.

    Published: 19 Nov 2011
    5
    Medium

    CVE-2011-4311

    Last Modified: 11 Apr 2025

    ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unspecified vectors.

    Published: 19 Nov 2011
    5
    Medium

    CVE-2011-4404

    Last Modified: 11 Apr 2025

    The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors, a related issue to CVE-2009-1523.

    Published: 19 Nov 2011
    4.3
    Medium

    CVE-2011-4465

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Lotus Mobile Connect (LMC) 6.1.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden redirect URL.

    Published: 19 Nov 2011
    7.5
    High

    CVE-2011-4088

    Last Modified: 26 Aug 2026

    ABRT might allow attackers to obtain sensitive information from crash reports.

    Published: 18 Nov 2011
    4.3
    Medium

    CVE-2011-4319

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an "html" substring.

    Published: 18 Nov 2011