CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2011-3876

    Last Modified: 11 Apr 2025

    Google Chrome before 15.0.874.102 does not properly handle downloading files that have whitespace characters at the end of a filename, which has unspecified impact and user-assisted remote attack vectors.

    Published: 25 Oct 2011
    6.8
    Medium

    CVE-2011-3878

    Last Modified: 11 Apr 2025

    Race condition in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to worker process initialization.

    Published: 25 Oct 2011
    7.5
    High

    CVE-2011-3879

    Last Modified: 11 Apr 2025

    Google Chrome before 15.0.874.102 does not prevent redirects to chrome: URLs, which has unspecified impact and remote attack vectors.

    Published: 25 Oct 2011
    7.5
    High

    CVE-2011-3880

    Last Modified: 11 Apr 2025

    Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact and remote attack vectors.

    Published: 25 Oct 2011
    7.5
    High

    CVE-2011-3882

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media buffers.

    Published: 25 Oct 2011
    7.5
    High

    CVE-2011-3883

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to counters.

    Published: 25 Oct 2011
    6.8
    Medium

    CVE-2011-3884

    Last Modified: 11 Apr 2025

    Google Chrome before 15.0.874.102 does not properly address timing issues during DOM traversal, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

    Published: 25 Oct 2011
    5
    Medium

    CVE-2011-3887

    Last Modified: 11 Apr 2025

    Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.

    Published: 25 Oct 2011
    6.8
    Medium

    CVE-2011-3888

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in conjunction with an unknown plug-in.

    Published: 25 Oct 2011
    7.5
    High

    CVE-2011-3889

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Web Audio implementation in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 25 Oct 2011
    7.5
    High

    CVE-2011-3890

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to video source handling.

    Published: 25 Oct 2011
    7.5
    High

    CVE-2011-3891

    Last Modified: 11 Apr 2025

    Google Chrome before 15.0.874.102 does not properly restrict access to internal Google V8 functions, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 25 Oct 2011
    4.3
    Medium

    CVE-2011-3881

    Last Modified: 11 Apr 2025

    WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selection object, (2) the Object::GetRealNamedPropertyInPrototypeChain function and use of an __proto__ property, (3) the HTMLPlugInImageElement::allowedToLoadFrameURL function and use of a javascript: URL, (4) incorrect origins for XSLT-generated documents in the XSLTProcessor::createDocumentFromSource function, and (5) improper handling of synchronous frame loads in the ScriptController::executeIfJavaScriptURL function.

    Published: 25 Oct 2011
    6.8
    Medium

    CVE-2011-3886

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers out-of-bounds write operations.

    Published: 25 Oct 2011
    4.3
    Medium

    CVE-2011-3877

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the appcache internals page in Google Chrome before 15.0.874.102 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Oct 2011
    7.5
    High

    CVE-2011-3885

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to stale Cascading Style Sheets (CSS) token-sequence data.

    Published: 25 Oct 2011
    4.3
    Medium

    CVE-2011-4171

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the project parameter to teamserver/faces/home.jsp.

    Published: 24 Oct 2011
    4.3
    Medium

    CVE-2011-4172

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in KENT-WEB WEB FORUM before 5.1 allow remote attackers to inject arbitrary web script or HTML via (1) an e-mail address field or (2) a cookie, a related issue to CVE-2011-3383, CVE-2011-3983, and CVE-2011-3984.

    Published: 24 Oct 2011
    6.8
    Medium

    CVE-2011-4173

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authentication of administrators or moderators via vectors involving image files, a different vulnerability than CVE-2011-3615. NOTE: some of these details are obtained from third party information.

    Published: 24 Oct 2011
    9.3
    Critical

    CVE-2011-2655

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in ZfHSrvr.exe in Novell ZENworks Handheld Management (ZHM) 7 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2656.

    Published: 24 Oct 2011
    9.3
    Critical

    CVE-2011-2656

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in ZfHSrvr.exe in Novell ZENworks Handheld Management (ZHM) 7 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2655.

    Published: 24 Oct 2011
    4.3
    Medium

    CVE-2011-3983

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to cookies.

    Published: 24 Oct 2011
    4.3
    Medium

    CVE-2011-3984

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to "web form entries."

    Published: 24 Oct 2011
    4.3
    Medium

    CVE-2011-3383

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to "the web page to be output."

    Published: 24 Oct 2011
    7.5
    High

    CVE-2011-3615

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via vectors involving a (1) HTML entity or (2) display name. NOTE: some of these details are obtained from third party information.

    Published: 24 Oct 2011
    2.1
    Low

    CVE-2011-3149

    Last Modified: 11 Apr 2025

    The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows local users to cause a denial of service (CPU consumption).

    Published: 24 Oct 2011
    2.6
    Low

    CVE-2011-3872

    Last Modified: 11 Apr 2025

    Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."

    Published: 24 Oct 2011
    4.6
    Medium

    CVE-2011-3148

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long string of white spaces at the beginning of the ~/.pam_environment file.

    Published: 24 Oct 2011
    4.3
    Medium

    CVE-2011-4170

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted alias (aka nickname) in a /me event, a different vulnerability than CVE-2011-3635.

    Published: 23 Oct 2011
    1.2
    Low

    CVE-2011-3163

    Last Modified: 11 Apr 2025

    HP MFP Digital Sending Software 4.9x through 4.91.21 allows local users to obtain sensitive workflow-metadata information via unspecified vectors.

    Published: 23 Oct 2011
    4.3
    Medium

    CVE-2011-3635

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted alias (aka nickname).

    Published: 23 Oct 2011
    7.5
    High

    CVE-2011-1640

    Last Modified: 11 Apr 2025

    The ethernet-lldp component in Cisco IOS 12.2 before 12.2(33)SXJ1 does not properly support a large number of LLDP Management Address (MA) TLVs, which allows remote attackers to cause a denial of service (device crash) via crafted LLDPDUs, aka Bug ID CSCtj22354.

    Published: 22 Oct 2011
    5
    Medium

    CVE-2011-2042

    Last Modified: 11 Apr 2025

    The Sybase SQL Anywhere database component in Cisco CiscoWorks Common Services 3.x and 4.x before 4.1 allows remote attackers to obtain potentially sensitive information about the engine name and database port via an unspecified request to UDP port 2638, aka Bug ID CSCsk35018.

    Published: 22 Oct 2011
    7.5
    High

    CVE-2011-2058

    Last Modified: 11 Apr 2025

    The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pair of dot1x enabled ports, which allows remote attackers to cause a denial of service (traffic storm) via unspecified vectors that trigger many unicast EAPoL Protocol Data Units (PDUs), aka Bug ID CSCtq36336.

    Published: 22 Oct 2011
    5
    Medium

    CVE-2011-2059

    Last Modified: 11 Apr 2025

    The ipv6 component in Cisco IOS before 15.1(4)M1.3 allows remote attackers to conduct fingerprinting attacks and obtain potentially sensitive information about the presence of the IOS operating system via an ICMPv6 Echo Request packet containing a Hop-by-Hop (HBH) extension header (EH) with a 0x0c01050c value in the PadN option data, aka Bug ID CSCtq02219.

    Published: 22 Oct 2011
    4.9
    Medium

    CVE-2011-2060

    Last Modified: 11 Apr 2025

    The platform-sw component on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 before 8.2(5.3), 8.3 before 8.3(2.20), and 8.4 before 8.4(2.1) does not properly handle non-ASCII characters in an interface description, which allows local users to cause a denial of service (reload without configuration) via a crafted description, aka Bug ID CSCtq50523.

    Published: 22 Oct 2011
    7.5
    High

    CVE-2011-2057

    Last Modified: 11 Apr 2025

    The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle (1) a loop between a dot1x enabled port and an open-authentication dot1x enabled port and (2) a loop between a dot1x enabled port and a non-dot1x port, which allows remote attackers to cause a denial of service (traffic storm) via unspecified vectors that trigger many Spanning Tree Protocol (STP) Bridge Protocol Data Unit (BPDU) frames, aka Bug ID CSCtq36327.

    Published: 22 Oct 2011
    5.5
    Medium

    CVE-2011-2677

    Last Modified: 11 Apr 2025

    Cybozu Office before 8.0.0 allows remote authenticated users to bypass intended access restrictions and access sensitive information (time card and attendance) via unspecified vectors related to manipulation of a URL.

    Published: 21 Oct 2011
    7.5
    High

    CVE-2011-3988

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in data/class/SC_Query.php in EC-CUBE 2.11.0 through 2.11.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Oct 2011
    4.3
    Medium

    CVE-2011-4024

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Oct 2011
    7.5
    High

    CVE-2011-4026

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in thanks.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Oct 2011
    7.5
    High

    CVE-2009-5102

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bpe_nid parameter.

    Published: 21 Oct 2011
    4.3
    Medium

    CVE-2010-4966

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in default.asp in ATCOM Netvolution allows remote attackers to inject arbitrary web script or HTML via the query parameter in a Search action.

    Published: 21 Oct 2011
    7.5
    High

    CVE-2010-4967

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL commands via the artID parameter.

    Published: 21 Oct 2011
    6.5
    Medium

    CVE-2011-0290

    Last Modified: 11 Apr 2025

    The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors.

    Published: 21 Oct 2011
    6.8
    Medium

    CVE-2011-4063

    Last Modified: 11 Apr 2025

    chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.7.1 and 10.x before 10.0.0-rc1 does not properly initialize variables during request parsing, which allows remote authenticated users to cause a denial of service (daemon crash) via a malformed request.

    Published: 21 Oct 2011
    4.3
    Medium

    CVE-2009-5103

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the email variable.

    Published: 21 Oct 2011
    7.5
    High

    CVE-2011-3340

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.

    Published: 21 Oct 2011
    4.3
    Medium

    CVE-2011-4102

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the erf_read_header function in wiretap/erf.c in the ERF file parser in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (application crash) via a malformed file.

    Published: 21 Oct 2011
    7.5
    High

    CVE-2011-2584

    Last Modified: 11 Apr 2025

    Cisco Show and Share 5(2), 5.2(1), and 5.2(2) before 5.2(2.1) allows remote attackers to access the (1) Encoders and Pull Configurations, (2) Push Configurations, (3) Video Encoding Formats, and (4) Transcoding administration pages, and cause a denial of service (live event outage) or obtain potentially sensitive information, via unspecified vectors, aka Bug ID CSCto73758.

    Published: 20 Oct 2011