CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2011-3274

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device crash) via a crafted IPv6 packet, related to an expired MPLS TTL, aka Bug ID CSCto07919.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-3281

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco IOS 15.0 through 15.1, in certain HTTP Layer 7 Application Control and Inspection configurations, allows remote attackers to cause a denial of service (device reload or hang) via a crafted HTTP packet, aka Bug ID CSCto68554.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-0939

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows remote attackers to cause a denial of service (device reload) via a crafted SIP message, aka Bug ID CSCth03022.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-3272

    Last Modified: 11 Apr 2025

    The IP Service Level Agreement (IP SLA) functionality in Cisco IOS 15.1, and IOS XE 2.1.x through 3.3.x, allows remote attackers to cause a denial of service (memory corruption and device reload) via malformed IP SLA packets, aka Bug ID CSCtk67073.

    Published: 3 Oct 2011
    7.8
    High

    CVE-2011-3282

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device reload) via an ICMPv6 packet, related to an expired MPLS TTL, aka Bug ID CSCtj30155.

    Published: 3 Oct 2011
    2.6
    Low

    CVE-2011-3975

    Last Modified: 11 Apr 2025

    A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified other devices, provides the HtcLoggers.apk application, which allows user-assisted remote attackers to obtain a list of telephone numbers from a log, and other sensitive information, by leveraging the android.permission.INTERNET application permission and establishing TCP sessions to 127.0.0.1 on port 65511 and a second port.

    Published: 3 Oct 2011
    9.8
    Critical

    CVE-2011-2767

    Last Modified: 21 Nov 2024

    mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.

    Published: 3 Oct 2011
    4.3
    Medium

    CVE-2011-3365

    Last Modified: 11 Apr 2025

    The KDE SSL Wrapper (KSSL) API in KDE SC 4.6.0 through 4.7.1, and possibly earlier versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.

    Published: 3 Oct 2011
    9
    Critical

    CVE-2011-2411

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on HP NonStop Servers with software H06.x through H06.23.00 and J06.x through J06.12.00, when Samba is used, allows remote authenticated users to execute arbitrary code via unknown vectors.

    Published: 2 Oct 2011
    5
    Medium

    CVE-2011-3974

    Last Modified: 11 Apr 2025

    Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, a different vulnerability than CVE-2011-3362.

    Published: 2 Oct 2011
    6.8
    Medium

    CVE-2011-3362

    Last Modified: 11 Apr 2025

    Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in FFmpeg before 0.7.3 and 0.8.x before 0.8.2, and libav through 0.7.1, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Chinese AVS video (aka CAVS) file.

    Published: 2 Oct 2011
    5
    Medium

    CVE-2011-3973

    Last Modified: 11 Apr 2025

    cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream in a Chinese AVS video (aka CAVS) file, related to the decode_residual_block, check_for_slice, and cavs_decode_frame functions, a different vulnerability than CVE-2011-3362.

    Published: 2 Oct 2011
    4.3
    Medium

    CVE-2011-3371

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in include/functions.php in PunBB before 1.3.6 allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) form_sent, (3) csrf_token, (4) req_confirm, or (5) delete parameter to delete.php, the (6) id, (7) form_sent, (8) csrf_token, (9) req_message, or (10) submit parameter to edit.php, the (11) action, (12) form_sent, (13) csrf_token, (14) req_email, or (15) request_pass parameter to login.php, the (16) email, (17) form_sent, (18) redirect_url, (19) csrf_token, (20) req_subject, (21) req_message, or (22) submit parameter to misc.php, the (23) action, (24) id, (25) form_sent, (26) csrf_token, (27) req_old_password, (28) req_new_password1, (29) req_new_password2, or (30) update parameter to profile.php, or the (31) action, (32) form_sent, (33) csrf_token, (34) req_username, (35) req_password1, (36) req_password2, (37) req_email1, (38) timezone, or (39) register parameter to register.php.

    Published: 2 Oct 2011
    7.5
    High

    CVE-2011-0553

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the management console in Symantec IM Manager before 8.4.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 2 Oct 2011
    7.5
    High

    CVE-2011-0554

    Last Modified: 11 Apr 2025

    The management console in Symantec IM Manager before 8.4.18 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "code injection issue."

    Published: 2 Oct 2011
    4.3
    Medium

    CVE-2011-2673

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in BaserCMS before 1.6.13.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Oct 2011
    4.9
    Medium

    CVE-2011-2674

    Last Modified: 11 Apr 2025

    BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors.

    Published: 2 Oct 2011
    4.3
    Medium

    CVE-2011-0552

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec IM Manager before 8.4.18 allow remote attackers to inject arbitrary web script or HTML via the (1) refreshRateSetting parameter to IMManager/Admin/IMAdminSystemDashboard.asp, the (2) nav or (3) menuitem parameter to IMManager/Admin/IMAdminTOC_simple.asp, or the (4) action parameter to IMManager/Admin/IMAdminEdituser.asp.

    Published: 2 Oct 2011
    7.5
    High

    CVE-2011-3597

    Last Modified: 11 Apr 2025

    Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new constructor.

    Published: 2 Oct 2011
    4.4
    Medium

    CVE-2011-3376

    Last Modified: 11 Apr 2025

    org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality.

    Published: 1 Oct 2011
    5
    Medium

    CVE-2011-3369

    Last Modified: 11 Apr 2025

    The add_conversation function in conversations.c in EtherApe before 0.9.12 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RPC packet, related to the get_rpc function in decode_proto.c.

    Published: 30 Sept 2011
    5
    Medium

    CVE-2011-3580

    Last Modified: 11 Apr 2025

    IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to obtain configuration information via a direct request to the /server URI, which triggers a call to the phpinfo function.

    Published: 30 Sept 2011
    6.4
    Medium

    CVE-2011-3579

    Last Modified: 11 Apr 2025

    server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference.

    Published: 30 Sept 2011
    4.3
    Medium

    CVE-2011-3010

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCreateNewTopic action, related to the TWiki.WebCreateNewTopicTemplate topic; or (2) the query string to SlideShow.pm in the SlideShowPlugin.

    Published: 30 Sept 2011
    6.2
    Medium

    CVE-2011-3871

    Last Modified: 11 Apr 2025

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editing arbitrary files.

    Published: 30 Sept 2011
    6.3
    Medium

    CVE-2011-3870

    Last Modified: 11 Apr 2025

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.

    Published: 30 Sept 2011
    6.3
    Medium

    CVE-2011-3869

    Last Modified: 11 Apr 2025

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.

    Published: 30 Sept 2011
    10
    Critical

    CVE-2011-3003

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 7.0 and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unspecified WebGL test case that triggers a memory-allocation error and a resulting out-of-bounds write operation.

    Published: 29 Sept 2011
    9.3
    Critical

    CVE-2011-3005

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OGG headers in a .ogg file.

    Published: 29 Sept 2011
    9.3
    Critical

    CVE-2011-3504

    Last Modified: 11 Apr 2025

    The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file.

    Published: 29 Sept 2011
    5
    Medium

    CVE-2011-3848

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double-encoded key parameter in the URI in 2.7.x, (2) the CN in the Subject of a CSR in 2.6 and 0.25.

    Published: 29 Sept 2011
    4.3
    Medium

    CVE-2011-3866

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion data events, which makes it easier for remote attackers to read keystrokes by leveraging JavaScript code running in a background tab.

    Published: 29 Sept 2011
    Unknown

    CVE-2011-3867

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-2998. Reason: This candidate is a duplicate of CVE-2011-2998. Notes: All CVE users should reference CVE-2011-2998 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Sept 2011
    4.3
    Medium

    CVE-2011-3001

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.

    Published: 29 Sept 2011
    4.3
    Medium

    CVE-2011-3594

    Last Modified: 11 Apr 2025

    The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2.

    Published: 29 Sept 2011
    10
    Critical

    CVE-2011-2997

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 29 Sept 2011
    9.3
    Critical

    CVE-2011-3002

    Last Modified: 11 Apr 2025

    Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 7.0 and SeaMonkey before 2.4, does not validate the return value of a GrowAtomTable function call, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a memory-allocation error and a resulting buffer overflow.

    Published: 29 Sept 2011
    4.3
    Medium

    CVE-2011-3004

    Last Modified: 11 Apr 2025

    The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior.

    Published: 29 Sept 2011
    9.3
    Critical

    CVE-2011-3232

    Last Modified: 11 Apr 2025

    YARR, as used in Mozilla Firefox before 7.0, Thunderbird before 7.0, and SeaMonkey before 2.4, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.

    Published: 29 Sept 2011
    4.3
    Medium

    CVE-2011-3851

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the News theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3853

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Hybrid theme before 0.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3854

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the ZenLite theme before 4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3855

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the F8 Lite theme before 4.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3856

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Elegant Grunge theme before 1.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3857

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Antisnews theme before 1.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3858

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme before 2.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3859

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Trending theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3860

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Cover WP theme before 1.6.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3862

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Morning Coffee theme before 3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3863

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the RedLine theme before 1.66 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 28 Sept 2011