CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-4968

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the webmaster-tips.net Flash Gallery (com_wmtpic) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4982

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in address_book/contacts.php in My Kazaam Address & Contact Organizer allows remote attackers to execute arbitrary SQL commands via the var1 parameter.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4991

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the NinjaMonials (com_ninjamonials) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a display action to index.php.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2010-4995

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the NeoRecruit (com_neorecruit) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in an offer_view action to index.php, a different vector than CVE-2007-4506.

    Published: 1 Nov 2011
    4.3
    Medium

    CVE-2011-4064

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.

    Published: 1 Nov 2011
    10
    Critical

    CVE-2011-4214

    Last Modified: 11 Apr 2025

    OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges via a crafted oozimsrememberme cookie.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2011-4215

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the cookieName variable.

    Published: 1 Nov 2011
    9.3
    Critical

    CVE-2011-4216

    Last Modified: 11 Apr 2025

    Investintech.com SlimPDF Reader does not properly restrict write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.

    Published: 1 Nov 2011
    9.3
    Critical

    CVE-2011-4217

    Last Modified: 11 Apr 2025

    Investintech.com SlimPDF Reader does not properly restrict read operations during block data moves, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.

    Published: 1 Nov 2011
    9.3
    Critical

    CVE-2011-4218

    Last Modified: 11 Apr 2025

    Investintech.com SlimPDF Reader does not prevent faulting-instruction data from affecting write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.

    Published: 1 Nov 2011
    9.3
    Critical

    CVE-2011-4219

    Last Modified: 11 Apr 2025

    Investintech.com SlimPDF Reader does not prevent faulting-address data from affecting branch selection, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.

    Published: 1 Nov 2011
    9.3
    Critical

    CVE-2011-4221

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document.

    Published: 1 Nov 2011
    9.3
    Critical

    CVE-2011-4222

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document.

    Published: 1 Nov 2011
    9.3
    Critical

    CVE-2011-4223

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Investintech.com Absolute PDF Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.

    Published: 1 Nov 2011
    7.8
    High

    CVE-2011-0941

    Last Modified: 11 Apr 2025

    Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1), and Cisco IOS 12.4 and 15.1, allows remote attackers to cause a denial of service (memory consumption and process failure or device reload) via a malformed SIP message, aka Bug IDs CSCti75128 and CSCtj09179.

    Published: 1 Nov 2011
    7.5
    High

    CVE-2011-1915

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in eClient 7.3.2.3 in Enspire Distribution Management Solution 7.3.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 1 Nov 2011
    9.3
    Critical

    CVE-2011-4220

    Last Modified: 11 Apr 2025

    Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.

    Published: 1 Nov 2011
    2.1
    Low

    CVE-2011-4132

    Last Modified: 11 Apr 2025

    The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2.6 allows local users to cause a denial of service (assertion error and kernel oops) via an ext3 or ext4 image with an "invalid log first block value."

    Published: 1 Nov 2011
    5.5
    Medium

    CVE-2011-4097

    Last Modified: 11 Apr 2025

    Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64-bit platforms allows local users to cause a denial of service (memory consumption or process termination) by using a certain large amount of memory.

    Published: 31 Oct 2011
    4.1
    Medium

    CVE-2009-0900

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the client in IBM WebSphere MQ 6.0 before 6.0.2.7 and 7.0 before 7.0.1.0 allows local users to gain privileges via crafted SSL information in a Client Channel Definition Table (CCDT) file.

    Published: 30 Oct 2011
    6.8
    Medium

    CVE-2011-1364

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in _ah/admin/interactive/execute (aka the Interactive Console) in the SDK Console (aka Admin Console) in the Google App Engine Python SDK before 1.5.4 allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary Python code via the code parameter.

    Published: 30 Oct 2011
    7.2
    High

    CVE-2011-4211

    Last Modified: 11 Apr 2025

    The FakeFile implementation in the sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly control the opening of files, which allows local users to bypass intended access restrictions and create arbitrary files via ALLOWED_MODES and ALLOWED_DIRS changes within the code parameter to _ah/admin/interactive/execute, a different vulnerability than CVE-2011-1364.

    Published: 30 Oct 2011
    7.2
    High

    CVE-2011-4212

    Last Modified: 11 Apr 2025

    The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent os.popen calls, which allows local users to bypass intended access restrictions and execute arbitrary commands via a dev_appserver.RestrictedPathFunction._original_os reference within the code parameter to _ah/admin/interactive/execute, a different vulnerability than CVE-2011-1364.

    Published: 30 Oct 2011
    7.2
    High

    CVE-2011-4213

    Last Modified: 11 Apr 2025

    The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent use of the os module, which allows local users to bypass intended access restrictions and execute arbitrary commands via a file_blob_storage.os reference within the code parameter to _ah/admin/interactive/execute, a different vulnerability than CVE-2011-1364.

    Published: 30 Oct 2011
    1.7
    Low

    CVE-2009-0905

    Last Modified: 11 Apr 2025

    IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with the same initial substring.

    Published: 30 Oct 2011
    5
    Medium

    CVE-2009-2747

    Last Modified: 11 Apr 2025

    The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows remote attackers to obtain sensitive information via a crafted method call.

    Published: 30 Oct 2011
    4.3
    Medium

    CVE-2009-2748

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Oct 2011
    8.8
    High

    CVE-2011-1366

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Import feature in IBM Rational AppScan Enterprise and AppScan Reporting Console 5.2 through 7.9.x and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary commands on an agent server via a crafted ZIP archive.

    Published: 30 Oct 2011
    9.3
    Critical

    CVE-2011-1367

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the File Load feature in IBM Rational AppScan Standard and Express 7.8.x, 7.9.x, and 8.0.x before 8.0.0.3 allows remote attackers to execute arbitrary commands via a crafted .scan file.

    Published: 30 Oct 2011
    5
    Medium

    CVE-2011-1370

    Last Modified: 11 Apr 2025

    The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authentication requirement, which allows remote attackers to read the configuration settings by examining a response message.

    Published: 29 Oct 2011
    4.3
    Medium

    CVE-2010-0780

    Last Modified: 11 Apr 2025

    IBM WebSphere MQ 7.x before 7.0.1.4 allows remote attackers to cause a denial of service (disk consumption) via multiple connection attempts to a stopped queue manager.

    Published: 29 Oct 2011
    5
    Medium

    CVE-2011-1368

    Last Modified: 11 Apr 2025

    The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which allows remote attackers to read unspecified files via unknown vectors.

    Published: 29 Oct 2011
    4.3
    Medium

    CVE-2011-1360

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to inject arbitrary web script or HTML via vectors involving unspecified documentation files in (1) manual/ibm/ and (2) htdocs/*/manual/ibm/.

    Published: 28 Oct 2011
    4.3
    Medium

    CVE-2011-1371

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an Unknown Error document, a different vulnerability than CVE-2011-4171.

    Published: 28 Oct 2011
    7.5
    High

    CVE-2011-2830

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 14.0.835.163, does not properly implement script object wrappers, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.

    Published: 28 Oct 2011
    9.3
    Critical

    CVE-2011-3247

    Last Modified: 11 Apr 2025

    Integer overflow in Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT file.

    Published: 28 Oct 2011
    9.3
    Critical

    CVE-2011-3250

    Last Modified: 11 Apr 2025

    Integer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.

    Published: 28 Oct 2011
    9.3
    Critical

    CVE-2011-3251

    Last Modified: 11 Apr 2025

    Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted TKHD atoms in a QuickTime movie file.

    Published: 28 Oct 2011
    9.3
    Critical

    CVE-2011-3248

    Last Modified: 11 Apr 2025

    Integer signedness error in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font table in a QuickTime movie file.

    Published: 28 Oct 2011
    9.3
    Critical

    CVE-2011-3249

    Last Modified: 11 Apr 2025

    Buffer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with FLC encoding.

    Published: 28 Oct 2011
    4
    Medium

    CVE-2011-4073

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the cryptographic helper handler functionality in Openswan 2.3.0 through 2.6.36 allows remote authenticated users to cause a denial of service (pluto IKE daemon crash) via vectors related to the (1) quick_outI1_continue and (2) quick_outI1 functions.

    Published: 28 Oct 2011
    6.8
    Medium

    CVE-2011-2569

    Last Modified: 11 Apr 2025

    Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, which allows local users to gain privileges via unspecified vectors, aka Bug IDs CSCtf40008, CSCtg18363, CSCtr44645, CSCts10195, and CSCts10188.

    Published: 27 Oct 2011
    9.3
    Critical

    CVE-2011-4004

    Last Modified: 11 Apr 2025

    Buffer overflow in the ATAS32 processing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute arbitrary code via a crafted WRF file.

    Published: 27 Oct 2011
    7.8
    High

    CVE-2011-3315

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.

    Published: 27 Oct 2011
    7.8
    High

    CVE-2011-3318

    Last Modified: 11 Apr 2025

    Cisco Video Surveillance 2421 and 2500 series cameras with software 1.1.x and 2.x before 2.4.0 and Video Surveillance 2600 series cameras with software before 4.2.0-13 allow remote attackers to cause a denial of service (device reload) by sending crafted RTSP packets over TCP, aka Bug IDs CSCtj96312, CSCtj39462, and CSCtl80175.

    Published: 27 Oct 2011
    9.3
    Critical

    CVE-2011-3319

    Last Modified: 11 Apr 2025

    Buffer overflow in the WRF parsing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute arbitrary code via a crafted WRF file.

    Published: 27 Oct 2011
    6.4
    Medium

    CVE-2011-4566

    Last Modified: 11 Apr 2025

    Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.

    Published: 27 Oct 2011
    4.3
    Medium

    CVE-2011-3639

    Last Modified: 11 Apr 2025

    The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP/0.9 protocol with a malformed URI containing an initial @ (at sign) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.

    Published: 26 Oct 2011
    4.3
    Medium

    CVE-2011-2845

    Last Modified: 11 Apr 2025

    Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.

    Published: 25 Oct 2011
    4.3
    Medium

    CVE-2011-3875

    Last Modified: 11 Apr 2025

    Google Chrome before 15.0.874.102 does not properly handle drag and drop operations on URL strings, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.

    Published: 25 Oct 2011