CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2011-3348

    Last Modified: 11 Apr 2025

    The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.

    Published: 14 Sept 2011
    6.5
    Medium

    CVE-2010-4834

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types parameter in a show_item_search action in the search_management_manage subcontroller. NOTE: some of these details are obtained from third party information.

    Published: 13 Sept 2011
    4
    Medium

    CVE-2010-4835

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action.

    Published: 13 Sept 2011
    4.3
    Medium

    CVE-2010-4836

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in register.html in PHPShop 2.1 EE and earlier allows remote attackers to inject arbitrary web script or HTML via the name_new parameter.

    Published: 13 Sept 2011
    6
    Medium

    CVE-2010-4838

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote authenticated users, with Public Back-end permissions, to execute arbitrary SQL commands via the alpha parameter in a (1) listTickets or (2) listFaqs action to administrator/index.php.

    Published: 13 Sept 2011
    4.3
    Medium

    CVE-2010-4837

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the JSupport (com_jsupport) component 1.5.6 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the subject parameter (title field) in a saveTicket action to index2.php. NOTE: some of these details are obtained from third party information.

    Published: 13 Sept 2011
    7.5
    High

    CVE-2010-4839

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action.

    Published: 13 Sept 2011
    4.3
    Medium

    CVE-2009-5096

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Flag Content module 5.x-2.x before 5.x-2.10 for Drupal allows remote attackers to inject arbitrary web script or HTML via the Reason parameter.

    Published: 13 Sept 2011
    7.1
    High

    CVE-2009-5097

    Last Modified: 11 Apr 2025

    Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3.

    Published: 13 Sept 2011
    5.4
    Medium

    CVE-2009-5098

    Last Modified: 11 Apr 2025

    The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of service (crash) via a web page containing a long string following a refresh tag, which triggers a floating point exception.

    Published: 13 Sept 2011
    4.3
    Medium

    CVE-2009-5099

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ViewAction in Pentaho BI Server 1.7.0.1062 and earlier allows remote attackers to inject arbitrary web script or HTML via the outputType parameter.

    Published: 13 Sept 2011
    2.1
    Low

    CVE-2009-5100

    Last Modified: 11 Apr 2025

    Pentaho BI Server 1.7.0.1062 and earlier does not set the autocomplete tag to off on web pages using a password field, which might allow physically proximate attackers to obtain the password.

    Published: 13 Sept 2011
    5
    Medium

    CVE-2009-5101

    Last Modified: 11 Apr 2025

    Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic.

    Published: 13 Sept 2011
    9.3
    Critical

    CVE-2011-2431

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allow attackers to execute arbitrary code via unspecified vectors, related to a "security bypass vulnerability."

    Published: 13 Sept 2011
    9.3
    Critical

    CVE-2011-2432

    Last Modified: 11 Apr 2025

    Buffer overflow in the U3D TIFF Resource in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 13 Sept 2011
    9.3
    Critical

    CVE-2011-2433

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2434 and CVE-2011-2437.

    Published: 13 Sept 2011
    9.3
    Critical

    CVE-2011-2434

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2433 and CVE-2011-2437.

    Published: 13 Sept 2011
    9.3
    Critical

    CVE-2011-2437

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2433 and CVE-2011-2434.

    Published: 13 Sept 2011
    9.3
    Critical

    CVE-2011-2438

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the image-parsing library in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allow attackers to execute arbitrary code via unspecified vectors.

    Published: 13 Sept 2011
    9.3
    Critical

    CVE-2011-2439

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allow attackers to execute arbitrary code via unspecified vectors, related to a "memory leakage condition vulnerability."

    Published: 13 Sept 2011
    9.3
    Critical

    CVE-2011-2440

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 13 Sept 2011
    9.3
    Critical

    CVE-2011-2442

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allow attackers to execute arbitrary code via unspecified vectors, related to a "logic error vulnerability."

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3433

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3451

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3455

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3456

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3461

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3465

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3466

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3467

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3468

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3469

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3470

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3471

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3472

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3473

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3474

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3475

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    9.3
    Critical

    CVE-2011-4374

    Last Modified: 11 Apr 2025

    Integer overflow in Adobe Reader 9.x before 9.4.6 on Linux allows attackers to execute arbitrary code via unspecified vectors.

    Published: 13 Sept 2011
    9.3
    Critical

    CVE-2011-2436

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the image-parsing library in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3445

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    Unknown

    CVE-2011-3454

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 13 Sept 2011
    9.3
    Critical

    CVE-2011-2435

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 13 Sept 2011
    4.3
    Medium

    CVE-2010-4340

    Last Modified: 11 Apr 2025

    libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.

    Published: 11 Sept 2011
    10
    Critical

    CVE-2011-3421

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.125 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

    Published: 10 Sept 2011
    10
    Critical

    CVE-2011-3420

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.157 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

    Published: 10 Sept 2011
    4.3
    Medium

    CVE-2011-3422

    Last Modified: 11 Apr 2025

    The Keychain implementation in Apple Mac OS X 10.6.8 and earlier does not properly handle an untrusted attribute of a Certification Authority certificate, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via an Extended Validation certificate, as demonstrated by https access with Safari.

    Published: 10 Sept 2011
    5
    Medium

    CVE-2009-5087

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request.

    Published: 9 Sept 2011
    7.5
    High

    CVE-2009-5088

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL commands via the cID parameter.

    Published: 9 Sept 2011
    4.3
    Medium

    CVE-2009-5089

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

    Published: 9 Sept 2011