CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2011-3290

    Last Modified: 11 Apr 2025

    Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other administrative actions via unknown vectors, aka Bug ID CSCts59135.

    Published: 21 Sept 2011
    9.3
    Critical

    CVE-2011-2427

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the ActionScript Virtual Machine (AVM) component in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows attackers to execute arbitrary code or cause a denial of service via unspecified vectors.

    Published: 21 Sept 2011
    9.3
    Critical

    CVE-2011-2430

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to execute arbitrary code via crafted streaming media, related to a "logic error vulnerability."

    Published: 21 Sept 2011
    5
    Medium

    CVE-2011-2429

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, related to a "security control bypass."

    Published: 21 Sept 2011
    8.5
    High

    CVE-2010-4818

    Last Modified: 11 Apr 2025

    The GLX extension in X.Org xserver 1.7.7 allows remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via (1) a crafted request that triggers a client swap in glx/glxcmdsswap.c; or (2) a crafted length or (3) a negative value in the screen field in a request to glx/glxcmds.c.

    Published: 21 Sept 2011
    9.3
    Critical

    CVE-2011-2426

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the ActionScript Virtual Machine (AVM) component in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 21 Sept 2011
    9.3
    Critical

    CVE-2011-2428

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows attackers to execute arbitrary code or cause a denial of service (browser crash) via unspecified vectors, related to a "logic error issue."

    Published: 21 Sept 2011
    4.3
    Medium

    CVE-2011-2444

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "universal cross-site scripting issue," as exploited in the wild in September 2011.

    Published: 21 Sept 2011
    5
    Medium

    CVE-2011-1509

    Last Modified: 11 Apr 2025

    The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

    Published: 20 Sept 2011
    4.3
    Medium

    CVE-2011-1510

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus (SDP) before 8012 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter.

    Published: 20 Sept 2011
    6.8
    Medium

    CVE-2011-1911

    Last Modified: 11 Apr 2025

    JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach.

    Published: 20 Sept 2011
    4.3
    Medium

    CVE-2011-2672

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in SemanticScuttle before 0.98 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Sept 2011
    10
    Critical

    CVE-2011-3577

    Last Modified: 11 Apr 2025

    IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which has unspecified impact and attack vectors.

    Published: 20 Sept 2011
    6.8
    Medium

    CVE-2011-2859

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspecified impact and attack vectors.

    Published: 17 Sept 2011
    7.5
    High

    CVE-2011-2860

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to table styles.

    Published: 17 Sept 2011
    6.8
    Medium

    CVE-2011-2861

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not properly handle strings in PDF documents, which allows remote attackers to have an unspecified impact via a crafted document that triggers an incorrect read operation.

    Published: 17 Sept 2011
    7.7
    High

    CVE-2011-1740

    Last Modified: 11 Apr 2025

    EMC Avamar 4.x, 5.0.x, and 6.0.x before 6.0.0-592 allows remote authenticated users to modify client data or obtain sensitive information about product activities by leveraging privileged access to a different domain.

    Published: 17 Sept 2011
    6.8
    Medium

    CVE-2011-2835

    Last Modified: 11 Apr 2025

    Race condition in Google Chrome before 14.0.835.163 allows attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the certificate cache.

    Published: 17 Sept 2011
    7.5
    High

    CVE-2011-2836

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not require Infobar interaction before use of the Windows Media Player plug-in, which makes it easier for remote attackers to have an unspecified impact via crafted Flash content.

    Published: 17 Sept 2011
    7.5
    High

    CVE-2011-2837

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 on Linux does not use the PIC and PIE compiler options for position-independent code, which has unspecified impact and attack vectors.

    Published: 17 Sept 2011
    7.5
    High

    CVE-2011-2838

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not properly consider the MIME type during the loading of a plug-in, which has unspecified impact and remote attack vectors.

    Published: 17 Sept 2011
    7.5
    High

    CVE-2011-2842

    Last Modified: 11 Apr 2025

    The installer in Google Chrome before 14.0.835.163 on Mac OS X does not properly handle lock files, which has unspecified impact and attack vectors.

    Published: 17 Sept 2011
    5
    Medium

    CVE-2011-2843

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not properly handle media buffers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 17 Sept 2011
    5
    Medium

    CVE-2011-2844

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not properly process MP3 files, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 17 Sept 2011
    6.8
    Medium

    CVE-2011-2846

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to unload event handling.

    Published: 17 Sept 2011
    6.8
    Medium

    CVE-2011-2847

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the document loader in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

    Published: 17 Sept 2011
    4.3
    Medium

    CVE-2011-2848

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to the forward button.

    Published: 17 Sept 2011
    5
    Medium

    CVE-2011-2850

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not properly handle Khmer characters, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 17 Sept 2011
    5
    Medium

    CVE-2011-2851

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not properly handle video, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 17 Sept 2011
    6.8
    Medium

    CVE-2011-2852

    Last Modified: 11 Apr 2025

    Off-by-one error in Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 17 Sept 2011
    7.5
    High

    CVE-2011-2853

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to plug-in handling.

    Published: 17 Sept 2011
    6.8
    Medium

    CVE-2011-2854

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "ruby / table style handing."

    Published: 17 Sept 2011
    7.5
    High

    CVE-2011-2856

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 17 Sept 2011
    5
    Medium

    CVE-2011-2864

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not properly handle Tibetan characters, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 17 Sept 2011
    6.8
    Medium

    CVE-2011-2874

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certificate during a session, which has unspecified impact and remote attack vectors.

    Published: 17 Sept 2011
    6.8
    Medium

    CVE-2011-2875

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 14.0.835.163, does not properly perform object sealing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

    Published: 17 Sept 2011
    5
    Medium

    CVE-2011-3234

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not properly handle boxes, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 17 Sept 2011
    2.1
    Low

    CVE-2011-3345

    Last Modified: 11 Apr 2025

    ulp/sdp/sdp_proc.c in the ib_sdp module (aka ib_sdp.ko) in the ofa_kernel package in the InfiniBand driver implementation in OpenFabrics Enterprise Distribution (OFED) before 1.5.3 does not properly handle certain non-array variables, which allows local users to cause a denial of service (stack memory corruption and system crash) by reading the /proc/net/sdpstats file.

    Published: 17 Sept 2011
    4.3
    Medium

    CVE-2011-3424

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in the Managed File Transfer server in TIBCO Managed File Transfer Internet Server before 7.1.1 and Managed File Transfer Command Center before 7.1.1, and the server in TIBCO Slingshot before 1.8.1, allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 17 Sept 2011
    6.8
    Medium

    CVE-2011-2834

    Last Modified: 11 Apr 2025

    Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

    Published: 17 Sept 2011
    6.8
    Medium

    CVE-2011-2841

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

    Published: 17 Sept 2011
    5
    Medium

    CVE-2011-2858

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not properly handle triangle arrays, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 17 Sept 2011
    7.5
    High

    CVE-2011-2862

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 14.0.835.163, does not properly restrict access to built-in objects, which has unspecified impact and remote attack vectors.

    Published: 17 Sept 2011
    4.3
    Medium

    CVE-2011-3576

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 8.5.2 allows remote attackers to inject arbitrary web script or HTML via the PanelIcon parameter in an fmpgPanelHeader ReadForm action to WebAdmin.nsf.

    Published: 17 Sept 2011
    10
    Critical

    CVE-2011-2738

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity Monitor (Ionix ACM) 2.3 and earlier, Adapter for Alcatel-Lucent 5620 SAM EMS (Ionix ASAM) 3.2.0.2 and earlier, IP Management Suite (Ionix IP) 8.1.1.1 and earlier, and other Ionix products; allow remote attackers to execute arbitrary code via crafted packets to TCP port 9002, aka Bug IDs CSCtn42961 and CSCtn64922, related to a buffer overflow.

    Published: 17 Sept 2011
    4.3
    Medium

    CVE-2011-2840

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to "unusual user interaction."

    Published: 17 Sept 2011
    4.3
    Medium

    CVE-2011-2849

    Last Modified: 11 Apr 2025

    The WebSockets implementation in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.

    Published: 17 Sept 2011
    6.8
    Medium

    CVE-2011-2855

    Last Modified: 11 Apr 2025

    Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."

    Published: 17 Sept 2011
    6.8
    Medium

    CVE-2011-2857

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the focus controller.

    Published: 17 Sept 2011
    4.3
    Medium

    CVE-2011-3423

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Managed File Transfer server in TIBCO Managed File Transfer Internet Server before 7.1.1 and Managed File Transfer Command Center before 7.1.1, and the server in TIBCO Slingshot before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Sept 2011