CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2011-3900

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 15.0.874.121, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write operation.

    Published: 17 Nov 2011
    2.6
    Low

    CVE-2011-4457

    Last Modified: 11 Apr 2025

    OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) before 88, when JavaScript is disabled, allows user-assisted remote attackers to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT element.

    Published: 17 Nov 2011
    4.3
    Medium

    CVE-2011-2770

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in man2html.cgi.c in man2html 1.6, and possibly other version, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to error messages.

    Published: 17 Nov 2011
    4.3
    Medium

    CVE-2011-3627

    Last Modified: 11 Apr 2025

    The bytecode engine in ClamAV before 0.97.3 allows remote attackers to cause a denial of service (crash) via vectors related to "recursion level" and (1) libclamav/bytecode.c and (2) libclamav/bytecode_api.c.

    Published: 17 Nov 2011
    5
    Medium

    CVE-2011-3646

    Last Modified: 11 Apr 2025

    phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to phpmyadmin.css.php, which reveals the installation path in an error message.

    Published: 17 Nov 2011
    6.9
    Medium

    CVE-2011-4122

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to kcheckpass.

    Published: 17 Nov 2011
    6.5
    Medium

    CVE-2011-4107

    Last Modified: 11 Apr 2025

    The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

    Published: 17 Nov 2011
    5.8
    Medium

    CVE-2011-4318

    Last Modified: 11 Apr 2025

    Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.

    Published: 17 Nov 2011
    6.4
    Medium

    CVE-2011-4358

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle GlassFish Enterprise Server 3.0.1 and 3.1.1 allows remote attackers to affect confidentiality and integrity, related to JSF.

    Published: 17 Nov 2011
    4.3
    Medium

    CVE-2011-4155

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0x and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4156.

    Published: 16 Nov 2011
    4.3
    Medium

    CVE-2011-4156

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0x and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4155.

    Published: 16 Nov 2011
    Unknown

    CVE-2011-4456

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4313. Reason: This candidate is a reservation duplicate of CVE-2011-4313. Notes: All CVE users should reference CVE-2011-4313 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Nov 2011
    10
    Critical

    CVE-2011-4157

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in hydra.exe in HP SAN/iQ before 9.5 on the HP StorageWorks P4000 Virtual SAN Appliance allows remote attackers to execute arbitrary code via a crafted login request.

    Published: 16 Nov 2011
    4
    Medium

    CVE-2011-4158

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Directories Support for ProLiant Management Processors 3.10 and 3.20 for Integrated Lights-Out iLO2 and iLO3 allows remote authenticated users to obtain sensitive information via unknown vectors.

    Published: 16 Nov 2011
    5
    Medium

    CVE-2011-4313

    Last Modified: 11 Apr 2025

    query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.

    Published: 16 Nov 2011
    7.5
    High

    CVE-2011-4405

    Last Modified: 11 Apr 2025

    The cupshelpers scripts in system-config-printer in Ubuntu 11.04 and 11.10, as used by the automatic printer driver download service, uses an "insecure connection" for queries to the OpenPrinting database, which allows remote attackers to execute arbitrary code via a man-in-the-middle (MITM) attack that modifies packages or repositories.

    Published: 16 Nov 2011
    6.8
    Medium

    CVE-2011-4085

    Last Modified: 11 Apr 2025

    The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method. NOTE: this vulnerability exists because of a CVE-2010-0738 regression.

    Published: 16 Nov 2011
    7.6
    High

    CVE-2008-7303

    Last Modified: 11 Apr 2025

    The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of launchctl to trigger the launchd daemon's execution of a script file, a related issue to CVE-2011-1516.

    Published: 15 Nov 2011
    7.6
    High

    CVE-2011-1516

    Last Modified: 11 Apr 2025

    The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of osascript to send Apple events to the launchd daemon, a related issue to CVE-2008-7303.

    Published: 15 Nov 2011
    5
    Medium

    CVE-2011-2772

    Last Modified: 11 Apr 2025

    The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.

    Published: 15 Nov 2011
    6.8
    Medium

    CVE-2011-2773

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Mahara before 1.4.1 allows remote attackers to hijack the authentication of administrators for requests that add a user to an institution.

    Published: 15 Nov 2011
    4
    Medium

    CVE-2011-2774

    Last Modified: 11 Apr 2025

    The "Reply to message" feature in Mahara 1.3.x and 1.4.x before 1.4.1 allows remote authenticated users to read the messages of a different user via a modified replyto parameter.

    Published: 15 Nov 2011
    6
    Medium

    CVE-2011-4118

    Last Modified: 11 Apr 2025

    Mahara before 1.4.1, when MNet (aka the Moodle network feature) is used, allows remote authenticated users to gain privileges via a jump to an XMLRPC target.

    Published: 15 Nov 2011
    4.3
    Medium

    CVE-2011-2771

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) URI attributes and (2) the External Feed component, as demonstrated by the guid element in an RSS feed.

    Published: 15 Nov 2011
    2.1
    Low

    CVE-2011-4110

    Last Modified: 11 Apr 2025

    The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."

    Published: 15 Nov 2011
    5.7
    Medium

    CVE-2011-3593

    Last Modified: 11 Apr 2025

    A certain Red Hat patch to the vlan_hwaccel_do_receive function in net/8021q/vlan_core.c in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows remote attackers to cause a denial of service (system crash) via priority-tagged VLAN frames.

    Published: 15 Nov 2011
    6
    Medium

    CVE-2011-4966

    Last Modified: 11 Apr 2025

    modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.

    Published: 14 Nov 2011
    5
    Medium

    CVE-2011-4046

    Last Modified: 11 Apr 2025

    The Dell KACE K2000 System Deployment Appliance stores the recovery account password in cleartext within a PHP script, which allows context-dependent attackers to obtain sensitive information by examining script source code.

    Published: 12 Nov 2011
    9.3
    Critical

    CVE-2011-4047

    Last Modified: 11 Apr 2025

    The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access.

    Published: 12 Nov 2011
    4.3
    Medium

    CVE-2011-4048

    Last Modified: 11 Apr 2025

    The Dell KACE K2000 System Deployment Appliance has a default username and password for the read-only reporting account, which makes it easier for remote attackers to obtain sensitive information from the database by leveraging the default credentials.

    Published: 12 Nov 2011
    3.5
    Low

    CVE-2011-4436

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface on the Dell KACE K2000 System Deployment Appliance allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 12 Nov 2011
    4.9
    Medium

    CVE-2011-1375

    Last Modified: 11 Apr 2025

    IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, which allows local users to cause a denial of service (system crash) via a crafted call.

    Published: 11 Nov 2011
    5
    Medium

    CVE-2011-4435

    Last Modified: 11 Apr 2025

    The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent directory browsing, which allows remote attackers to obtain sensitive information via HTTP requests.

    Published: 11 Nov 2011
    3.6
    Low

    CVE-2011-4434

    Last Modified: 11 Apr 2025

    Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLocker rules, which allows local users to bypass intended access restrictions via a (1) macro or (2) scripting feature in an application, as demonstrated by Microsoft Office applications and the SANDBOX_INERT and LOAD_IGNORE_CODE_AUTHZ_LEVEL flags.

    Published: 11 Nov 2011
    1.2
    Low

    CVE-2011-3440

    Last Modified: 11 Apr 2025

    The Passcode Lock feature in Apple iOS before 5.0.1 on the iPad 2 does not properly implement the locked state, which allows physically proximate attackers to access data by opening a Smart Cover during power-off confirmation.

    Published: 11 Nov 2011
    4.3
    Medium

    CVE-2011-3441

    Last Modified: 11 Apr 2025

    libinfo in Apple iOS before 5.0.1 does not properly formulate domain-name queries, which allows remote attackers to obtain sensitive information via a crafted DNS hostname.

    Published: 11 Nov 2011
    7.2
    High

    CVE-2011-3442

    Last Modified: 11 Apr 2025

    The kernel in Apple iOS before 5.0.1 does not ensure the validity of flag combinations for an mmap system call, which allows local users to execute arbitrary unsigned code via a crafted app.

    Published: 11 Nov 2011
    9.3
    Critical

    CVE-2011-2458

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, when Internet Explorer is used, allows remote attackers to bypass the cross-domain policy via a crafted web site.

    Published: 11 Nov 2011
    5
    Medium

    CVE-2011-3893

    Last Modified: 11 Apr 2025

    Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 11 Nov 2011
    7.5
    High

    CVE-2011-3896

    Last Modified: 11 Apr 2025

    Buffer overflow in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to shader variable mapping.

    Published: 11 Nov 2011
    6.8
    Medium

    CVE-2011-3897

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing.

    Published: 11 Nov 2011
    7.5
    High

    CVE-2011-3892

    Last Modified: 11 Apr 2025

    Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.

    Published: 11 Nov 2011
    7.5
    High

    CVE-2011-3894

    Last Modified: 11 Apr 2025

    Google Chrome before 15.0.874.120 does not properly perform VP8 decoding, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted stream.

    Published: 11 Nov 2011
    7.5
    High

    CVE-2011-3895

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.

    Published: 11 Nov 2011
    7.5
    High

    CVE-2011-3898

    Last Modified: 11 Apr 2025

    Google Chrome before 15.0.874.120, when Java Runtime Environment (JRE) 7 is used, does not request user confirmation before applet execution begins, which allows remote attackers to have an unspecified impact via a crafted applet.

    Published: 11 Nov 2011
    10
    Critical

    CVE-2011-2445

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, CVE-2011-2459, and CVE-2011-2460.

    Published: 10 Nov 2011
    10
    Critical

    CVE-2011-2452

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, CVE-2011-2459, and CVE-2011-2460.

    Published: 10 Nov 2011
    10
    Critical

    CVE-2011-2453

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2454, CVE-2011-2455, CVE-2011-2459, and CVE-2011-2460.

    Published: 10 Nov 2011
    10
    Critical

    CVE-2011-2454

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2455, CVE-2011-2459, and CVE-2011-2460.

    Published: 10 Nov 2011
    10
    Critical

    CVE-2011-2457

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code via unspecified vectors.

    Published: 10 Nov 2011