CVE Feed

    Dashboard / CVE

    8.5
    High

    CVE-2008-7300

    Last Modified: 11 Apr 2025

    The labeled networking implementation in Solaris Trusted Extensions in Sun Solaris 10 and OpenSolaris snv_39 through snv_67, when a labeled zone is in the installed state, allows remote authenticated users to bypass a Mandatory Access Control (MAC) policy and obtain access to the global zone.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2008-7301

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in admin/login.php in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2008-7302

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in netinvoice.php in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving "knowledge of ... the contents of an encrypted file."

    Published: 5 Oct 2011
    4.3
    Medium

    CVE-2011-0459

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cyber-Ark Password Vault Web Access (PVWA) 5.0 and earlier, 5.5 through 5.5 patch 4, and 6.0 through 6.0 patch 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Oct 2011
    4.9
    Medium

    CVE-2011-1076

    Last Modified: 11 Apr 2025

    net/dns_resolver/dns_key.c in the Linux kernel before 2.6.38 allows remote DNS servers to cause a denial of service (NULL pointer dereference and OOPS) by not providing a valid response to a DNS query, as demonstrated by an erroneous grand.centrall.org query, which triggers improper handling of error data within a DNS resolver key.

    Published: 5 Oct 2011
    9.3
    Critical

    CVE-2011-1827

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distributed by SecurePlatform, IPSO6, Connectra, and VSX, allow remote attackers to execute arbitrary code via vectors involving a (1) ActiveX control or (2) Java applet.

    Published: 5 Oct 2011
    2.1
    Low

    CVE-2000-1247

    Last Modified: 11 Apr 2025

    The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.

    Published: 5 Oct 2011
    7.5
    High

    CVE-2011-3372

    Last Modified: 11 Apr 2025

    imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.

    Published: 5 Oct 2011
    5
    Medium

    CVE-2011-3380

    Last Modified: 11 Apr 2025

    Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.

    Published: 5 Oct 2011
    5.7
    Medium

    CVE-2011-3589

    Last Modified: 11 Apr 2025

    The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, uses world-readable permissions for vmcore files, which allows local users to obtain sensitive information by inspecting the file content, as demonstrated by a search for a root SSH key.

    Published: 5 Oct 2011
    5
    Medium

    CVE-2011-3368

    Last Modified: 11 Apr 2025

    The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.

    Published: 5 Oct 2011
    5.7
    Medium

    CVE-2011-3588

    Last Modified: 11 Apr 2025

    The SSH configuration in the Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, disables the StrictHostKeyChecking option, which allows man-in-the-middle attackers to spoof kdump servers, and obtain sensitive core information, by using an arbitrary SSH key.

    Published: 5 Oct 2011
    5.7
    Medium

    CVE-2011-3590

    Last Modified: 11 Apr 2025

    The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, includes all of root's SSH private keys within a vmcore file, which allows context-dependent attackers to obtain sensitive information by inspecting the file content.

    Published: 5 Oct 2011
    4.3
    Medium

    CVE-2011-1221

    Last Modified: 11 Apr 2025

    Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document, a different vulnerability than CVE-2011-2947.

    Published: 4 Oct 2011
    6.8
    Medium

    CVE-2011-2876

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 14.0.835.202 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a text line box.

    Published: 4 Oct 2011
    6.8
    Medium

    CVE-2011-2877

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.202 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale font."

    Published: 4 Oct 2011
    6.8
    Medium

    CVE-2011-3873

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.202 does not properly implement shader translation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 4 Oct 2011
    6.8
    Medium

    CVE-2011-2880

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 14.0.835.202 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the Google V8 bindings.

    Published: 4 Oct 2011
    6.8
    Medium

    CVE-2011-2881

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.202 does not properly handle Google V8 hidden objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.

    Published: 4 Oct 2011
    9.3
    Critical

    CVE-2011-2443

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted (1) .grd or (2) .abr file, a related issue to CVE-2010-1296.

    Published: 4 Oct 2011
    7.5
    High

    CVE-2011-2878

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.202 does not properly restrict access to the window prototype, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 4 Oct 2011
    6.8
    Medium

    CVE-2011-2879

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.202 does not properly consider object lifetimes and thread safety during the handling of audio nodes, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 4 Oct 2011
    7.5
    High

    CVE-2011-3980

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Drag Drop Mass Upload (ameos_dragndropupload) extension 2.0.2 and earlier for TYPO3 allows remote attackers to upload arbitrary files via unknown vectors.

    Published: 4 Oct 2011
    7.5
    High

    CVE-2011-3981

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

    Published: 4 Oct 2011
    6.8
    Medium

    CVE-2011-1572

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Admin Defined Commands (ADC) feature in gitolite before 1.5.9.1 allows remote attackers to execute arbitrary commands via .. (dot dot) sequences in admin-defined commands.

    Published: 4 Oct 2011
    6.8
    Medium

    CVE-2011-3976

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST command, as demonstrated using (1) GETLIST or (2) GETFILE in a ScriptFTP script.

    Published: 4 Oct 2011
    3.5
    Low

    CVE-2011-3978

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php in LightNEasy 3.2.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) commentemail, (2) commentmessage, or (3) commentname parameter in a sendcomment action for the news page.

    Published: 4 Oct 2011
    5
    Medium

    CVE-2011-3354

    Last Modified: 11 Apr 2025

    The CtcpParser::packedReply method in core/ctcpparser.cpp in Quassel before 0.7.3 allows remote attackers to cause a denial of service (crash) via a crafted Client-To-Client Protocol (CTCP) request, as demonstrated in the wild in September 2011.

    Published: 4 Oct 2011
    7.2
    High

    CVE-2011-3977

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in nxconfigure.sh in NoMachine NX Node 3.x before 3.5.0-4 and NX Server 3.x before 3.5.0-5 allows local users to read arbitrary files via unknown vectors.

    Published: 4 Oct 2011
    4.3
    Medium

    CVE-2011-3979

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application Framework 1.3.0 build 3168, 1.2.7, and probably other versions allows remote attackers to inject arbitrary web script or HTML via the themename parameter in the setasdefault action to index.php.

    Published: 4 Oct 2011
    4.3
    Medium

    CVE-2011-2713

    Last Modified: 11 Apr 2025

    oowriter in OpenOffice.org 3.3.0 and LibreOffice before 3.4.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers an out-of-bounds read in the DOC sprm parser.

    Published: 4 Oct 2011
    6.4
    Medium

    CVE-2011-3602

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in device-linux.c in the router advertisement daemon (radvd) before 1.8.2 allows local users to overwrite arbitrary files, and remote attackers to overwrite certain files, via a .. (dot dot) in an interface name. NOTE: this can be leveraged with a symlink to overwrite arbitrary files.

    Published: 4 Oct 2011
    4.4
    Medium

    CVE-2011-3603

    Last Modified: 12 Apr 2025

    The router advertisement daemon (radvd) before 1.8.2 does not properly handle errors in the privsep_init function, which causes the radvd daemon to run as root and has an unspecified impact.

    Published: 4 Oct 2011
    5
    Medium

    CVE-2011-3605

    Last Modified: 11 Apr 2025

    The process_rs function in the router advertisement daemon (radvd) before 1.8.2, when UnicastOnly is enabled, allows remote attackers to cause a denial of service (temporary service hang) via a large number of ND_ROUTER_SOLICIT requests.

    Published: 4 Oct 2011
    7.5
    High

    CVE-2011-3601

    Last Modified: 11 Apr 2025

    Buffer overflow in the process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative value in a label_len value.

    Published: 4 Oct 2011
    7.5
    High

    CVE-2011-3604

    Last Modified: 11 Apr 2025

    The process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attackers to cause a denial of service (stack-based buffer over-read and crash) via unspecified vectors.

    Published: 4 Oct 2011
    9.3
    Critical

    CVE-2011-4030

    Last Modified: 11 Apr 2025

    The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerability than CVE-2011-3587.

    Published: 4 Oct 2011
    7.8
    High

    CVE-2011-0944

    Last Modified: 11 Apr 2025

    Cisco IOS 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (device reload) via malformed IPv6 packets, aka Bug ID CSCtj41194.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-0945

    Last Modified: 11 Apr 2025

    Memory leak in the Data-link switching (aka DLSw) feature in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xS before 3.1.3S and 3.2.xS before 3.2.1S, when implemented over Fast Sequence Transport (FST), allows remote attackers to cause a denial of service (memory consumption and device reload or hang) via a crafted IP protocol 91 packet, aka Bug ID CSCth69364.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-0946

    Last Modified: 11 Apr 2025

    The NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) via malformed NetMeeting Directory (aka Internet Locator Service or ILS) LDAP traffic, aka Bug ID CSCtd10712.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-2072

    Last Modified: 11 Apr 2025

    Memory leak in Cisco IOS 12.4, 15.0, and 15.1, Cisco IOS XE 2.5.x through 3.2.x, and Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su4, 8.x before 8.5(1)su2, and 8.6 before 8.6(1) allows remote attackers to cause a denial of service (memory consumption and device reload or process failure) via a malformed SIP message, aka Bug IDs CSCtl86047 and CSCto88686.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-3270

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco IOS 12.2SB before 12.2(33)SB10 and 15.0S before 15.0(1)S3a on Cisco 10000 series routers allows remote attackers to cause a denial of service (device reload) via a sequence of crafted ICMP packets, aka Bug ID CSCtk62453.

    Published: 3 Oct 2011
    10
    Critical

    CVE-2011-3271

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Smart Install functionality in Cisco IOS 12.2 and 15.1 allows remote attackers to execute arbitrary code or cause a denial of service (device crash) via crafted TCP packets to port 4786, aka Bug ID CSCto10165.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-3275

    Last Modified: 11 Apr 2025

    Memory leak in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted SIP message, aka Bug ID CSCti48504.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-3276

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) by sending crafted SIP packets to TCP port 5060, aka Bug ID CSCso02147.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-3277

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) by sending crafted H.323 packets to TCP port 1720, aka Bug ID CSCth11006.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-3278

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) by sending crafted SIP packets to UDP port 5060, aka Bug ID CSCti48483.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-3279

    Last Modified: 11 Apr 2025

    The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) via a malformed SIP packet to UDP port 5060, aka Bug ID CSCti98219.

    Published: 3 Oct 2011
    7.5
    High

    CVE-2011-3280

    Last Modified: 11 Apr 2025

    Memory leak in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (memory consumption or device reload) by sending crafted SIP packets to UDP port 5060, aka Bug ID CSCtj04672.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-3273

    Last Modified: 11 Apr 2025

    Memory leak in Cisco IOS 15.0 through 15.1, when IPS or Zone-Based Firewall (aka ZBFW) is configured, allows remote attackers to cause a denial of service (memory consumption or device crash) via vectors that trigger many session creation flows, aka Bug ID CSCti79848.

    Published: 3 Oct 2011