CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2011-2459

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, and CVE-2011-2460.

    Published: 10 Nov 2011
    10
    Critical

    CVE-2011-2460

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, and CVE-2011-2459.

    Published: 10 Nov 2011
    6.5
    Medium

    CVE-2011-4431

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. (dot dot) in the command_name parameter.

    Published: 10 Nov 2011
    5
    Medium

    CVE-2011-4432

    Last Modified: 11 Apr 2025

    www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to determine cleartext passwords via a rainbow-table approach.

    Published: 10 Nov 2011
    10
    Critical

    CVE-2011-2450

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 10 Nov 2011
    10
    Critical

    CVE-2011-2451

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, CVE-2011-2459, and CVE-2011-2460.

    Published: 10 Nov 2011
    10
    Critical

    CVE-2011-2456

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code via unspecified vectors.

    Published: 10 Nov 2011
    9.3
    Critical

    CVE-2011-3439

    Last Modified: 11 Apr 2025

    FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.

    Published: 10 Nov 2011
    10
    Critical

    CVE-2011-2455

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2459, and CVE-2011-2460.

    Published: 10 Nov 2011
    1.5
    Low

    CVE-2011-1373

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (STMM) feature and the AUTOMATIC DATABASE_MEMORY setting are configured, allows local users to cause a denial of service (daemon crash) via unknown vectors.

    Published: 9 Nov 2011
    8.5
    High

    CVE-2011-2739

    Last Modified: 11 Apr 2025

    The file-blocking feature in EMC Documentum eRoom 7.3.x and 7.4.x before 7.4.3.g does not properly restrict the uploading and opening of files with dangerous file types, which allows remote authenticated users to execute arbitrary code via an uploaded file.

    Published: 9 Nov 2011
    9.3
    Critical

    CVE-2011-2740

    Last Modified: 11 Apr 2025

    EMC RSA Key Manager (RKM) Appliance 2.7 SP1 before 2.7.1.6, when Firefox 4.x or 5.0 is used, does not properly terminate a user session upon a logout action, which makes it easier for remote attackers to execute arbitrary code by leveraging an unattended workstation.

    Published: 9 Nov 2011
    2.6
    Low

    CVE-2011-3985

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Plume before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Nov 2011
    7.5
    High

    CVE-2011-3997

    Last Modified: 11 Apr 2025

    Opengear console servers with firmware before 2.2.1 allow remote attackers to bypass authentication, and modify settings or access connected equipment, via unspecified vectors.

    Published: 9 Nov 2011
    4.3
    Medium

    CVE-2011-3999

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the RSS/Atom feed-reader implementation in Iwate Portal Bar allows remote attackers to inject arbitrary web script or HTML via a crafted feed.

    Published: 9 Nov 2011
    4.3
    Medium

    CVE-2011-3998

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Apple WebObjects 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Nov 2011
    2.6
    Low

    CVE-2011-3649

    Last Modified: 11 Apr 2025

    Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas. NOTE: this issue exists because of a CVE-2011-2986 regression.

    Published: 9 Nov 2011
    10
    Critical

    CVE-2011-3651

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 7.0 and Thunderbird 7.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 9 Nov 2011
    10
    Critical

    CVE-2011-3654

    Last Modified: 11 Apr 2025

    The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly handle links from SVG mpath elements to non-SVG elements, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

    Published: 9 Nov 2011
    9.3
    Critical

    CVE-2011-3655

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 7.0 and Thunderbird 5.0 through 7.0 perform access control without checking for use of the NoWaiverWrapper wrapper, which allows remote attackers to gain privileges via a crafted web site.

    Published: 9 Nov 2011
    5
    Medium

    CVE-2011-3653

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel integrated GPUs, which allows remote attackers to bypass the Same Origin Policy and read image data via vectors related to WebGL textures.

    Published: 9 Nov 2011
    10
    Critical

    CVE-2011-3652

    Last Modified: 11 Apr 2025

    The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly allocate memory, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

    Published: 9 Nov 2011
    6.1
    Medium

    CVE-2011-3656

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.

    Published: 9 Nov 2011
    7.2
    High

    CVE-2011-4330

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the hfs_mac2asc function in fs/hfs/trans.c in the Linux kernel 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via an HFS image with a crafted len field.

    Published: 9 Nov 2011
    10
    Critical

    CVE-2011-2447

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 8 Nov 2011
    10
    Critical

    CVE-2011-2448

    Last Modified: 11 Apr 2025

    The DIRapi library in Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2446.

    Published: 8 Nov 2011
    10
    Critical

    CVE-2011-2449

    Last Modified: 11 Apr 2025

    The TextXtra module in Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 8 Nov 2011
    9.3
    Critical

    CVE-2011-4000

    Last Modified: 11 Apr 2025

    Buffer overflow in ChaSen 2.4.x allows remote attackers to execute arbitrary code via a crafted string.

    Published: 8 Nov 2011
    10
    Critical

    CVE-2011-2446

    Last Modified: 11 Apr 2025

    The DIRapi library in Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2448.

    Published: 8 Nov 2011
    7.1
    High

    CVE-2011-2004

    Last Modified: 11 Apr 2025

    Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2011-3402.

    Published: 8 Nov 2011
    9
    Critical

    CVE-2011-2014

    Last Modified: 11 Apr 2025

    The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not examine Certificate Revocation Lists (CRLs), which allows remote authenticated users to bypass intended certificate restrictions and access Active Directory resources by leveraging a revoked X.509 certificate for a domain account, aka "LDAPS Authentication Bypass Vulnerability."

    Published: 8 Nov 2011
    7.3
    High

    CVE-2011-2016

    Last Modified: 4 Jun 2025

    Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .eml or .wcinv file, aka "Windows Mail Insecure Library Loading Vulnerability."

    Published: 8 Nov 2011
    9.8
    Critical

    CVE-2011-2013

    Last Modified: 11 Apr 2025

    Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed port, aka "Reference Counter Overflow Vulnerability."

    Published: 8 Nov 2011
    4.3
    Medium

    CVE-2011-3377

    Last Modified: 11 Apr 2025

    The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.

    Published: 8 Nov 2011
    9.3
    Critical

    CVE-2011-3647

    Last Modified: 11 Apr 2025

    The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.

    Published: 8 Nov 2011
    4.3
    Medium

    CVE-2011-3648

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.

    Published: 8 Nov 2011
    9.3
    Critical

    CVE-2011-3650

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.

    Published: 8 Nov 2011
    5
    Medium

    CVE-2011-3168

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the POP and IMAP service implementations in HP TCP/IP Services 5.6 and 5.7 for OpenVMS allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 7 Nov 2011
    5
    Medium

    CVE-2011-3169

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the SMTP service implementation in HP TCP/IP Services 5.6 and 5.7 for OpenVMS allows remote attackers to cause a denial of service via unknown vectors.

    Published: 7 Nov 2011
    4.3
    Medium

    CVE-2011-4128

    Last Modified: 11 Apr 2025

    Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

    Published: 7 Nov 2011
    4.3
    Medium

    CVE-2011-1398

    Last Modified: 11 Apr 2025

    The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

    Published: 6 Nov 2011
    4.6
    Medium

    CVE-2011-4131

    Last Modified: 11 Apr 2025

    The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.

    Published: 5 Nov 2011
    6.8
    Medium

    CVE-2011-3581

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns before 1.6.11 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Resource Record (RR) with an unknown type containing input that is longer than a specified length.

    Published: 4 Nov 2011
    7.2
    High

    CVE-2011-3330

    Last Modified: 11 Apr 2025

    Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers, to execute arbitrary code via an unspecified system parameter.

    Published: 4 Nov 2011
    8.8
    High

    CVE-2011-3402

    Last Modified: 22 Apr 2026

    Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability."

    Published: 4 Nov 2011
    6.8
    Medium

    CVE-2011-3164

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP-UX Containers (formerly HP-UX Secure Resource Partitions (SRP)) A.03.00, A.03.00.002, and A.03.01, when running with patch PHKL_42310, allows local users to gain privileges via unknown vectors.

    Published: 4 Nov 2011
    7.5
    High

    CVE-2011-1513

    Last Modified: 11 Apr 2025

    Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.

    Published: 4 Nov 2011
    3.6
    Low

    CVE-2011-3171

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise Server and possibly other operating systems, when the Netware OES remote server feature is enabled, allows local users to overwrite arbitrary files via unknown vectors.

    Published: 4 Nov 2011
    7.5
    High

    CVE-2011-3989

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in DBD::mysqlPP 0.04 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 4 Nov 2011
    7.5
    High

    CVE-2011-4066

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

    Published: 4 Nov 2011