CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2011-3864

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the The Erudite theme before 2.7.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3865

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3850

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Atahualpa theme before 3.6.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3852

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the EvoLve theme before 1.2.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3861

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Minimalist 200901 theme before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

    Published: 28 Sept 2011
    8.8
    High

    CVE-2011-4952

    Last Modified: 21 Nov 2024

    cobbler: Web interface lacks CSRF protection when using Django framework

    Published: 28 Sept 2011
    10
    Critical

    CVE-2011-2995

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 28 Sept 2011
    10
    Critical

    CVE-2011-2996

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the plugin API in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 28 Sept 2011
    10
    Critical

    CVE-2011-2998

    Last Modified: 11 Apr 2025

    Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-2999

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a different vulnerability than CVE-2010-0170.

    Published: 28 Sept 2011
    9.3
    Critical

    CVE-2011-3587

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.

    Published: 28 Sept 2011
    4
    Medium

    CVE-2011-3638

    Last Modified: 11 Apr 2025

    fs/ext4/extents.c in the Linux kernel before 3.0 does not mark a modified extent as dirty in certain cases of extent splitting, which allows local users to cause a denial of service (system crash) via vectors involving ext4 umount and mount operations.

    Published: 28 Sept 2011
    6.8
    Medium

    CVE-2011-4953

    Last Modified: 12 Apr 2025

    The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet.

    Published: 28 Sept 2011
    7.8
    High

    CVE-2011-4954

    Last Modified: 21 Nov 2024

    cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE

    Published: 28 Sept 2011
    3.5
    Low

    CVE-2011-2372

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3000

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.

    Published: 28 Sept 2011
    4.3
    Medium

    CVE-2011-3686

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in myAddressBook.asp in Sonexis ConferenceManager 9.2.11.0 and 9.3.14.0 allow remote attackers to inject arbitrary web script or HTML via the (1) fname, (2) lname, (3) email_edit, (4) email, (5) email2, (6) email3, (7) sms, (8) sms_id, or (9) work parameter.

    Published: 27 Sept 2011
    7.5
    High

    CVE-2011-3688

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Sonexis ConferenceManager 9.3.14.0 allow remote attackers to execute arbitrary SQL commands via (1) the g parameter to Conference/Audio/AudioResourceContainer.asp or (2) the txtConferenceID parameter to Login/HostLogin.asp.

    Published: 27 Sept 2011
    9.3
    Critical

    CVE-2011-3690

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in PlotSoft PDFill PDF Editor 8.0 allows local users to gain privileges via a Trojan horse mfc70enu.dll or mfc80loc.dll in the current working directory.

    Published: 27 Sept 2011
    1.9
    Low

    CVE-2011-3692

    Last Modified: 11 Apr 2025

    NetSaro Enterprise Messenger Server 2.0 stores cleartext console credentials in configuration.xml, which allows local users to obtain sensitive information by reading this file and performing a base64 decoding step.

    Published: 27 Sept 2011
    1.9
    Low

    CVE-2011-3693

    Last Modified: 11 Apr 2025

    NetSaro Enterprise Messenger Server 2.0 allows local users to discover cleartext server credentials by reading the NetSaro.fdb file.

    Published: 27 Sept 2011
    5
    Medium

    CVE-2011-3694

    Last Modified: 11 Apr 2025

    The Server Administration Console in NetSaro Enterprise Messenger Server 2.0 allows remote attackers to read application source code by appending a %00 character to a URL.

    Published: 27 Sept 2011
    7.5
    High

    CVE-2010-4840

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.exe process crash) or possibly execute arbitrary code via a long Syslog PRI message header to UDP port (1) 513 or (2) 514. Fixed in 7.2 Build 7020.

    Published: 27 Sept 2011
    4.3
    Medium

    CVE-2010-4841

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HOST_ID, (2) OS, (3) GROUP, (4) exportFile, (5) load, (6) type, or (7) tab parameter to INDEX.do, the (8) reported parameter to INDEX2.do, the (9) gId parameter to hostlist.do, the (10) newWindow parameter to globalSettings.do, or the (11) STATUS parameter to enableHost.do. Fixed in Build 9000.

    Published: 27 Sept 2011
    4.3
    Medium

    CVE-2011-3684

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Tembria Server Monitor before 6.0.5 Build 2252 allow remote attackers to inject arbitrary web script or HTML via (1) the siteid parameter to logbook.asp, (2) the siteid parameter to monitor-events.asp, (3) the siteid parameter to reports-config-by-device.asp, (4) the siteid parameter to reports-config-by-monitor.asp, (5) the siteid parameter to reports-monitoring-queue.asp, (6) the action parameter to site-list.asp, the (7) siteid or (8) type parameter to event-history.asp, the (9) siteid or (10) type parameter to admin-history.asp, the (11) siteid or (12) id parameter to dashboard-view.asp, the (13) siteid or (14) dn parameter to device-events.asp, the (15) siteid or (16) submit parameter to device-finder.asp, the (17) siteid or (18) dn parameter to device-monitors.asp, the (19) siteid or (20) type parameter to device-views.asp, the (21) siteid or (22) type parameter to monitor-views.asp, the (23) siteid or (24) sel parameter to reports-list.asp, the (25) siteid, (26) action, or (27) sel parameter to monitor-list.asp, or the (28) siteid, (29) action, or (30) sel parameter to device-list.asp.

    Published: 27 Sept 2011
    1.9
    Low

    CVE-2011-3685

    Last Modified: 11 Apr 2025

    Tembria Server Monitor before 6.0.5 Build 2252 uses a substitution cipher to encrypt application credentials, which allows local users to obtain sensitive information by leveraging read access to (1) authentication.dat or (2) XML files in the Exports directory.

    Published: 27 Sept 2011
    7.5
    High

    CVE-2011-3645

    Last Modified: 11 Apr 2025

    Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which leads to arbitrary permission changes; or (2) a modified UserIndex parameter to doccab/userprofile/editprofile.jsp, which selects the settings page of an arbitrary user.

    Published: 27 Sept 2011
    4.3
    Medium

    CVE-2011-3687

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Sonexis ConferenceManager 9.2.11.0 allow remote attackers to inject arbitrary web script or HTML via (1) the txtConferenceID parameter to HostLogin.asp, (2) the txtConferenceID parameter to ParticipantLogin.asp, (3) the acp parameter to ForgotPIN.asp, or the (4) Description, (5) title, or (6) Heading parameter to Error.asp.

    Published: 27 Sept 2011
    4.3
    Medium

    CVE-2011-3689

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Licenses.html in Wibu-Systems CodeMeter WebAdmin 3.30 and 4.30 allows remote attackers to inject arbitrary web script or HTML via the BoxSerial parameter.

    Published: 27 Sept 2011
    9.3
    Critical

    CVE-2011-3691

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Foxit Reader before 5.0.2.0718 allows local users to gain privileges via a Trojan horse dwmapi.dll, dwrite.dll, or msdrm.dll in the current working directory.

    Published: 27 Sept 2011
    7.5
    High

    CVE-2010-4842

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote attackers to execute arbitrary SQL commands via the Name parameter. NOTE: some of these details are obtained from third party information.

    Published: 27 Sept 2011
    7.5
    High

    CVE-2010-4843

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in website-page.php in PHP Web Scripts Ad Manager Pro 3.0 allows remote attackers to execute arbitrary SQL commands via the pageId parameter.

    Published: 27 Sept 2011
    7.5
    High

    CVE-2010-4844

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary SQL commands via the kat parameter.

    Published: 27 Sept 2011
    7.5
    High

    CVE-2010-4845

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php.

    Published: 27 Sept 2011
    7.5
    High

    CVE-2010-4846

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in view_item.php in MH Products Pay Pal Shop Digital allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

    Published: 27 Sept 2011
    7.5
    High

    CVE-2010-4849

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in countrydetails.php in Alibaba Clone B2B 3.4 allows remote attackers to execute arbitrary SQL commands via the es_id parameter.

    Published: 27 Sept 2011
    7.5
    High

    CVE-2010-4851

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the (1) ref or (2) poll_id parameter to index.php, or the (3) country parameter to create_account.php.

    Published: 27 Sept 2011
    4.3
    Medium

    CVE-2010-4852

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in login.php in Eclime 1.1.2b allows remote attackers to inject arbitrary web script or HTML via the reason parameter in a fail action.

    Published: 27 Sept 2011
    4.3
    Medium

    CVE-2010-4848

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in addlink.php in AXScripts AxsLinks 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) title parameter.

    Published: 27 Sept 2011
    4.3
    Medium

    CVE-2010-4850

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Diferior 8.03 allow remote attackers to inject arbitrary web script or HTML via the (1) post_content parameter to post/edit/2/p1.html, related to views/post.php; the (2) slogan parameter to admin/site/2.html, related to views/admin.php; or the (3) subcatname or (4) description parameter to admin/forum/create_sub.html, related to views/admin.php.

    Published: 27 Sept 2011
    7.5
    High

    CVE-2010-4847

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

    Published: 27 Sept 2011
    9.3
    Critical

    CVE-2011-3378

    Last Modified: 11 Apr 2025

    RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.

    Published: 27 Sept 2011
    4.3
    Medium

    CVE-2011-2728

    Last Modified: 11 Apr 2025

    The bsd_glob function in the File::Glob module for Perl before 5.14.2 allows context-dependent attackers to cause a denial of service (crash) via a glob expression with the GLOB_ALTDIRFUNC flag, which triggers an uninitialized pointer dereference.

    Published: 26 Sept 2011
    5
    Medium

    CVE-2011-3324

    Last Modified: 11 Apr 2025

    The ospf6_lsa_is_changed function in ospf6_lsa.c in the OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via trailing zero values in the Link State Advertisement (LSA) header list of an IPv6 Database Description message.

    Published: 26 Sept 2011
    7.5
    High

    CVE-2011-3327

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the ecommunity_ecom2str function in bgp_ecommunity.c in bgpd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by sending a crafted BGP UPDATE message over IPv4.

    Published: 26 Sept 2011
    6.9
    Medium

    CVE-2011-3364

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly other versions, when PolicyKit is configured to allow users to create new connections, allows local users to execute arbitrary commands via a newline character in the name for a new network connection, which is not properly handled when writing to the ifcfg file.

    Published: 26 Sept 2011
    4.3
    Medium

    CVE-2011-5063

    Last Modified: 11 Apr 2025

    The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.

    Published: 26 Sept 2011
    4.3
    Medium

    CVE-2011-5064

    Last Modified: 11 Apr 2025

    DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.

    Published: 26 Sept 2011
    5
    Medium

    CVE-2011-1184

    Last Modified: 11 Apr 2025

    The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the expected countermeasures against replay attacks, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, related to lack of checking of nonce (aka server nonce) and nc (aka nonce-count or client nonce count) values.

    Published: 26 Sept 2011
    5
    Medium

    CVE-2011-3323

    Last Modified: 11 Apr 2025

    The OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a denial of service (out-of-bounds memory access and daemon crash) via a Link State Update message with an invalid IPv6 prefix length.

    Published: 26 Sept 2011