CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2011-3553

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote authenticated users to affect confidentiality, related to JAXWS.

    Published: 18 Oct 2011
    10
    Critical

    CVE-2011-3554

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 18 Oct 2011
    6.8
    Medium

    CVE-2011-3557

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3556.

    Published: 18 Oct 2011
    7.8
    High

    CVE-2011-3559

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Communications Server 2.0; GlassFish Enterprise Server 2.1.1, 3.0.1, and 3.1.1; and Sun Java System App Server 8.1 and 8.2 allows remote attackers to affect availability via unknown vectors related to Web Container.

    Published: 18 Oct 2011
    9
    Critical

    CVE-2010-4965

    Last Modified: 11 Apr 2025

    /etc/rc.d/rc.local on the D-Link DCS-2121 camera with firmware 1.04 configures a hardcoded password of admin for the root account, which makes it easier for remote attackers to obtain shell access by leveraging a running telnetd server.

    Published: 16 Oct 2011
    9
    Critical

    CVE-2010-4964

    Last Modified: 11 Apr 2025

    recorder_test.cgi on the D-Link DCS-2121 camera with firmware 1.04 allows remote attackers to execute arbitrary commands via shell metacharacters in the Password field, related to a "semicolon injection" vulnerability.

    Published: 16 Oct 2011
    8.8
    High

    CVE-2011-3631

    Last Modified: 21 Nov 2024

    Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and trick the local user into consolidating it, leading to hardlink executable crash or potentially arbitrary code execution with user privileges.

    Published: 15 Oct 2011
    7.1
    High

    CVE-2011-3632

    Last Modified: 21 Nov 2024

    Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.

    Published: 15 Oct 2011
    8.8
    High

    CVE-2011-3630

    Last Modified: 21 Nov 2024

    Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.

    Published: 15 Oct 2011
    6.8
    Medium

    CVE-2011-0229

    Last Modified: 11 Apr 2025

    Apple Type Services (ATS) in Apple Mac OS X through 10.6.8 does not properly handle embedded Type 1 fonts, which allows remote attackers to execute arbitrary code via a crafted document that triggers an out-of-bounds memory access.

    Published: 14 Oct 2011
    7.5
    High

    CVE-2011-0230

    Last Modified: 11 Apr 2025

    Buffer overflow in the ATSFontDeactivate API in Apple Type Services (ATS) in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

    Published: 14 Oct 2011
    5
    Medium

    CVE-2011-0231

    Last Modified: 11 Apr 2025

    CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to track users via a cookie, related to a "synchronization issue."

    Published: 14 Oct 2011
    4.6
    Medium

    CVE-2011-0260

    Last Modified: 11 Apr 2025

    The CoreProcesses component in Apple Mac OS X 10.7 before 10.7.2 does not prevent a system window from receiving keystrokes in the locked-screen state, which might allow physically proximate attackers to bypass intended access restrictions by typing into this window.

    Published: 14 Oct 2011
    7.6
    High

    CVE-2011-3213

    Last Modified: 11 Apr 2025

    The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.

    Published: 14 Oct 2011
    2.1
    Low

    CVE-2011-3215

    Last Modified: 11 Apr 2025

    The kernel in Apple Mac OS X before 10.7.2 does not properly prevent FireWire DMA in the absence of a login, which allows physically proximate attackers to bypass intended access restrictions and discover a password by making a DMA request in the (1) loginwindow, (2) boot, or (3) shutdown state.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3217

    Last Modified: 11 Apr 2025

    MediaKit in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image.

    Published: 14 Oct 2011
    4.3
    Medium

    CVE-2011-3220

    Last Modified: 11 Apr 2025

    QuickTime in Apple Mac OS X before 10.7.2 does not properly process URL data handlers in movie files, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3221

    Last Modified: 11 Apr 2025

    QuickTime in Apple Mac OS X before 10.7.2 does not properly handle the atom hierarchy in movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3222

    Last Modified: 11 Apr 2025

    Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.

    Published: 14 Oct 2011
    2.6
    Low

    CVE-2011-3224

    Last Modified: 11 Apr 2025

    The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to App Store help information, which allows man-in-the-middle attackers to execute arbitrary code by spoofing the http server.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3226

    Last Modified: 11 Apr 2025

    Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypass the password requirement by leveraging lack of an AuthenticationAuthority attribute for a user account.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3227

    Last Modified: 11 Apr 2025

    libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3228

    Last Modified: 11 Apr 2025

    QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3229

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Apple Safari before 5.1.1 allows remote attackers to execute arbitrary JavaScript code, in a Safari Extensions context, via a crafted safari-extension: URL.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3230

    Last Modified: 11 Apr 2025

    Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via a crafted web site.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3231

    Last Modified: 11 Apr 2025

    The SSL implementation in Apple Safari before 5.1.1 on Mac OS X before 10.7 accesses uninitialized memory during the processing of X.509 certificates, which allows remote web servers to execute arbitrary code via a crafted certificate.

    Published: 14 Oct 2011
    4.3
    Medium

    CVE-2011-3243

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.

    Published: 14 Oct 2011
    2.1
    Low

    CVE-2011-3245

    Last Modified: 11 Apr 2025

    The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent use of a keyboard, which allows physically proximate attackers to obtain sensitive information by reading this character.

    Published: 14 Oct 2011
    5
    Medium

    CVE-2011-3246

    Last Modified: 11 Apr 2025

    CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (1) http or (2) https URL.

    Published: 14 Oct 2011
    2.6
    Low

    CVE-2011-3253

    Last Modified: 11 Apr 2025

    CalDAV in Apple iOS before 5 does not validate X.509 certificates for SSL sessions, which allows man-in-the-middle attackers to spoof calendar servers and obtain sensitive information via an arbitrary certificate.

    Published: 14 Oct 2011
    4.3
    Medium

    CVE-2011-3254

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Calendar in Apple iOS before 5 allows remote attackers to inject arbitrary web script or HTML via an invitation note.

    Published: 14 Oct 2011
    5
    Medium

    CVE-2011-3259

    Last Modified: 11 Apr 2025

    The kernel in Apple iOS before 5 and Apple TV before 4.4 does not properly recover memory allocated for incomplete TCP connections, which allows remote attackers to cause a denial of service (resource consumption) by making many connection attempts.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3260

    Last Modified: 11 Apr 2025

    Buffer overflow in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word document.

    Published: 14 Oct 2011
    6.8
    Medium

    CVE-2011-3261

    Last Modified: 11 Apr 2025

    Double free vulnerability in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Excel spreadsheet.

    Published: 14 Oct 2011
    4.3
    Medium

    CVE-2011-3426

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary web script or HTML via a file accompanied by a "Content-Disposition: attachment" HTTP header.

    Published: 14 Oct 2011
    2.6
    Low

    CVE-2011-3427

    Last Modified: 11 Apr 2025

    The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain sensitive information via a crafted certificate.

    Published: 14 Oct 2011
    9.3
    Critical

    CVE-2011-3430

    Last Modified: 11 Apr 2025

    The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does not properly implement localization, which makes it easier for attackers to have an unspecified impact by leveraging incorrect configuration display.

    Published: 14 Oct 2011
    2.1
    Low

    CVE-2011-3431

    Last Modified: 11 Apr 2025

    The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which might allow physically proximate attackers to obtain sensitive state information by watching the device's screen.

    Published: 14 Oct 2011
    5
    Medium

    CVE-2011-3432

    Last Modified: 11 Apr 2025

    The UIKit Alerts component in Apple iOS before 5 allows remote attackers to cause a denial of service (device hang) via a long tel: URL that triggers a large size for the acceptance dialog.

    Published: 14 Oct 2011
    4.3
    Medium

    CVE-2011-3434

    Last Modified: 11 Apr 2025

    The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.

    Published: 14 Oct 2011
    2.1
    Low

    CVE-2011-3435

    Last Modified: 11 Apr 2025

    Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via unspecified vectors.

    Published: 14 Oct 2011
    6.5
    Medium

    CVE-2011-3436

    Last Modified: 11 Apr 2025

    Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended workstation.

    Published: 14 Oct 2011
    4.4
    Medium

    CVE-2011-0185

    Last Modified: 11 Apr 2025

    Format string vulnerability in the debug-logging feature in Application Firewall in Apple Mac OS X before 10.7.2 allows local users to gain privileges via a crafted name of an executable file.

    Published: 14 Oct 2011
    2.1
    Low

    CVE-2011-3212

    Last Modified: 11 Apr 2025

    CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate attackers to obtain sensitive information by reading directly from the disk device.

    Published: 14 Oct 2011
    4.6
    Medium

    CVE-2011-3214

    Last Modified: 11 Apr 2025

    IOGraphics in Apple Mac OS X through 10.6.8 does not properly handle a locked-screen state in display sleep mode for an Apple Cinema Display, which allows physically proximate attackers to bypass the password requirement via unspecified vectors.

    Published: 14 Oct 2011
    2.1
    Low

    CVE-2011-3216

    Last Modified: 11 Apr 2025

    The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow local users to bypass intended permissions and delete files via an unlink system call.

    Published: 14 Oct 2011
    5
    Medium

    CVE-2011-3225

    Last Modified: 11 Apr 2025

    The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-restricted folder, which allows remote attackers to bypass intended browsing restrictions by leveraging access to the nobody account.

    Published: 14 Oct 2011
    5
    Medium

    CVE-2011-3242

    Last Modified: 11 Apr 2025

    The Private Browsing feature in Apple Safari before 5.1.1 on Mac OS X does not properly recognize the Always value of the Block Cookies setting, which makes it easier for remote web servers to track users via a cookie.

    Published: 14 Oct 2011
    2.1
    Low

    CVE-2011-3257

    Last Modified: 11 Apr 2025

    The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the same mail server, which allows local users to bypass intended access restrictions in opportunistic circumstances by leveraging a different account's cookie.

    Published: 14 Oct 2011
    2.1
    Low

    CVE-2011-3429

    Last Modified: 11 Apr 2025

    The Settings component in Apple iOS before 5 stores a cleartext parental-restrictions passcode in an unspecified file, which might allow physically proximate attackers to obtain sensitive information by reading this file.

    Published: 14 Oct 2011