CVE Feed

    Dashboard / CVE

    9
    Critical

    CVE-2011-3575

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino 8.5.2 allows remote authenticated users to execute arbitrary code via a long tHPRAgentName parameter in an fmHttpPostRequest OpenForm action to WebAdmin.nsf.

    Published: 17 Sept 2011
    10
    Critical

    CVE-2011-3495

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to read, modify, or delete arbitrary files via the (1) RF, (2) wF, (3) UF, or (4) NF command.

    Published: 16 Sept 2011
    10
    Critical

    CVE-2011-3496

    Last Modified: 11 Apr 2025

    service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (2) OF, or (3) EF command.

    Published: 16 Sept 2011
    10
    Critical

    CVE-2011-3497

    Last Modified: 11 Apr 2025

    service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.

    Published: 16 Sept 2011
    10
    Critical

    CVE-2011-3498

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long request.

    Published: 16 Sept 2011
    10
    Critical

    CVE-2011-3499

    Last Modified: 11 Apr 2025

    Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an EIDP packet with a large size field, which writes a zero byte to an arbitrary memory location.

    Published: 16 Sept 2011
    5
    Medium

    CVE-2011-3502

    Last Modified: 11 Apr 2025

    The web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to obtain the source code of executable files via a request with a trailing (1) space or (2) %2e (encoded dot).

    Published: 16 Sept 2011
    5
    Medium

    CVE-2011-3501

    Last Modified: 11 Apr 2025

    Integer overflow in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to cause a denial of service (crash) via a negative or large Content-Length value.

    Published: 16 Sept 2011
    9.3
    Critical

    CVE-2011-3503

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in eSignal 10.6.2425.1208, and possibly other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse JRS_UT.dll that is located in the same folder as a .quo (QUOTE) file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 16 Sept 2011
    5
    Medium

    CVE-2011-3500

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request.

    Published: 16 Sept 2011
    10
    Critical

    CVE-2011-3488

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Equis MetaStock 11 and earlier allows remote attackers to execute arbitrary code via a malformed (1) mwc chart, (2) mws chart, (3) mwt template, or (4) mwl layout.

    Published: 16 Sept 2011
    10
    Critical

    CVE-2011-3491

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative Content-Length field.

    Published: 16 Sept 2011
    5
    Medium

    CVE-2011-3487

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in CarelDataServer.exe in Carel PlantVisor 2.4.4 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.

    Published: 16 Sept 2011
    10
    Critical

    CVE-2011-3490

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long command to port 11234, as demonstrated with the TF command.

    Published: 16 Sept 2011
    10
    Critical

    CVE-2011-3493

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the DH_OneSecondTick function in Cogent DataHub 7.1.1.63 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) domain, (2) report_domain, (3) register_datahub, or (4) slave commands.

    Published: 16 Sept 2011
    10
    Critical

    CVE-2011-3494

    Last Modified: 11 Apr 2025

    WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long StyleTemplate element in a QUO, SUM or POR file, which triggers a stack-based buffer overflow, or (2) a long Font->FaceName field (aka FaceName element), which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

    Published: 16 Sept 2011
    5
    Medium

    CVE-2011-3486

    Last Modified: 11 Apr 2025

    Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to UDP port 48899, which triggers an out-of-bounds read.

    Published: 16 Sept 2011
    5
    Medium

    CVE-2011-3489

    Last Modified: 11 Apr 2025

    RnaUtility.dll in RsvcHost.exe 2.30.0.23 in Rockwell RSLogix 19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted rna packet with a long string to TCP port 4446 that triggers (1) "a memset zero overflow" or (2) an out-of-bounds read, related to improper handling of a 32-bit size field.

    Published: 16 Sept 2011
    10
    Critical

    CVE-2011-3492

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted NETB packet to UDP port 20034.

    Published: 16 Sept 2011
    4.3
    Medium

    CVE-2011-4100

    Last Modified: 11 Apr 2025

    The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 16 Sept 2011
    9.3
    Critical

    CVE-2011-3321

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Siemens WinCC Runtime Advanced Loader, as used in SIMATIC WinCC flexible Runtime and SIMATIC WinCC (TIA Portal) Runtime Advanced, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted packet to TCP port 2308.

    Published: 15 Sept 2011
    9.3
    Critical

    CVE-2011-3211

    Last Modified: 11 Apr 2025

    The server in Bcfg2 1.1.2 and earlier, and 1.2 prerelease, allows remote attackers to execute arbitrary commands via shell metacharacters in data received from a client.

    Published: 15 Sept 2011
    10
    Critical

    CVE-2011-3322

    Last Modified: 11 Apr 2025

    Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password to the Telnet (TCP/23) port, which triggers an out-of-bounds read or write, leading to a stack-based buffer overflow.

    Published: 15 Sept 2011
    7.5
    High

    CVE-2011-2671

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Megalith 12th edition through 27th edition allows remote attackers to gain administrative privileges via unknown vectors.

    Published: 15 Sept 2011
    4.3
    Medium

    CVE-2011-3393

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in findagent.php in MYRE Real Estate Software allow remote attackers to inject arbitrary web script or HTML via the (1) country1, (2) state1, or (3) city1 parameter.

    Published: 15 Sept 2011
    7.5
    High

    CVE-2011-3394

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in findagent.php in MYRE Real Estate Software allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 15 Sept 2011
    6.9
    Medium

    CVE-2011-1353

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader 10.x before 10.1.1 on Windows allows local users to gain privileges via unknown vectors.

    Published: 15 Sept 2011
    4.3
    Medium

    CVE-2011-1893

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2, and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "SharePoint XSS Vulnerability."

    Published: 15 Sept 2011
    7.2
    High

    CVE-2011-1984

    Last Modified: 11 Apr 2025

    WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability."

    Published: 15 Sept 2011
    9.3
    Critical

    CVE-2011-1986

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability."

    Published: 15 Sept 2011
    9.3
    Critical

    CVE-2011-1990

    Last Modified: 11 Apr 2025

    Microsoft Excel 2007 SP2; Excel in Office 2007 SP2; Excel Viewer SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Excel Services on Office SharePoint Server 2007 SP2 do not properly validate the sign of an unspecified array index, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Out of Bounds Array Indexing Vulnerability."

    Published: 15 Sept 2011
    9.3
    Critical

    CVE-2011-2441

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in CoolType.dll in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allow attackers to execute arbitrary code via unspecified vectors.

    Published: 15 Sept 2011
    4
    Medium

    CVE-2011-1892

    Last Modified: 11 Apr 2025

    Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability."

    Published: 15 Sept 2011
    9.3
    Critical

    CVE-2011-1980

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft Office 2003 SP3 and 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .ppt, or .xls file, aka "Office Component Insecure Library Loading Vulnerability."

    Published: 15 Sept 2011
    9.3
    Critical

    CVE-2011-1982

    Last Modified: 11 Apr 2025

    Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Office Uninitialized Object Pointer Vulnerability."

    Published: 15 Sept 2011
    9.3
    Critical

    CVE-2011-1988

    Last Modified: 11 Apr 2025

    Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly parse records in Excel spreadsheets, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Heap Corruption Vulnerability."

    Published: 15 Sept 2011
    9.3
    Critical

    CVE-2011-1989

    Last Modified: 11 Apr 2025

    Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; Excel Services on Office SharePoint Server 2007 SP2; Excel Services on Office SharePoint Server 2010 Gold and SP1; and Excel Web App 2010 Gold and SP1 do not properly parse conditional expressions associated with formatting requirements, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Conditional Expression Parsing Vulnerability."

    Published: 15 Sept 2011
    9.3
    Critical

    CVE-2011-1991

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .rtf, or .txt file, related to (1) deskpan.dll in the Display Panning CPL Extension, (2) EAPHost Authenticator Service, (3) Folder Redirection, (4) HyperTerminal, (5) the Japanese Input Method Editor (IME), and (6) Microsoft Management Console (MMC), aka "Windows Components Insecure Library Loading Vulnerability."

    Published: 15 Sept 2011
    4.3
    Medium

    CVE-2011-0653

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."

    Published: 15 Sept 2011
    4.3
    Medium

    CVE-2011-1890

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."

    Published: 15 Sept 2011
    4.3
    Medium

    CVE-2011-1891

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."

    Published: 15 Sept 2011
    9.3
    Critical

    CVE-2011-1987

    Last Modified: 11 Apr 2025

    Array index error in Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Out of Bounds Array Indexing Vulnerability."

    Published: 15 Sept 2011
    5.4
    Medium

    CVE-2011-3344

    Last Modified: 3 Apr 2026

    A flaw was found in Spacewalk. A remote attacker can exploit a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form by injecting arbitrary web script or HTML via the URI. This can lead to information disclosure or unauthorized actions within the user's browser session.

    Published: 15 Sept 2011
    5.4
    Medium

    CVE-2011-2927

    Last Modified: 3 Apr 2026

    A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject malicious web scripts or HTML into web pages viewed by other users. The flaw is triggered through vectors related to Search forms, enabling attackers to potentially steal sensitive information or perform actions on behalf of the victim.

    Published: 15 Sept 2011
    5.5
    Medium

    CVE-2011-2920

    Last Modified: 2 Apr 2026

    A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web pages through various input fields, such as the "Filter by Synopsis" field. This could lead to the execution of malicious code in a user's web browser, potentially compromising user sessions or disclosing sensitive information.

    Published: 15 Sept 2011
    4.3
    Medium

    CVE-2011-2919

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to inject arbitrary web script or HTML via the QueryString to the SystemGroupList.do page.

    Published: 15 Sept 2011
    5
    Medium

    CVE-2011-1483

    Last Modified: 11 Apr 2025

    wsf/common/DOMUtils.java in JBossWS Native in Red Hat JBoss Enterprise Application Platform 4.2.0.CP09, 4.3, and 5.1.1; JBoss Enterprise Portal Platform 4.3.CP06 and 5.1.1; JBoss Enterprise SOA Platform 4.2.CP05, 4.3.CP05, and 5.1.0; JBoss Communications Platform 1.2.11 and 5.1.1; JBoss Enterprise BRMS Platform 5.1.0; and JBoss Enterprise Web Platform 5.1.1 does not properly handle recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted request containing an XML document with a DOCTYPE declaration and a large number of nested entity references, a similar issue to CVE-2003-1564.

    Published: 15 Sept 2011
    10
    Critical

    CVE-2011-2595

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code via a long id parameter in a (1) String or (2) Int tag in a FotoSlate Project (aka PLP) file.

    Published: 14 Sept 2011
    4.3
    Medium

    CVE-2011-2201

    Last Modified: 11 Apr 2025

    The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input.

    Published: 14 Sept 2011
    5
    Medium

    CVE-2011-2581

    Last Modified: 11 Apr 2025

    The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000 series switches, does not properly handle comments in conjunction with deny statements, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending packets, aka Bug IDs CSCto09813 and CSCtr61490.

    Published: 14 Sept 2011