CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2009-5090

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter and possibly other unspecified vectors.

    Published: 9 Sept 2011
    7.5
    High

    CVE-2009-5091

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 9 Sept 2011
    4.3
    Medium

    CVE-2009-5092

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management interface in Microsoft FAST ESP 5.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Sept 2011
    5
    Medium

    CVE-2009-5093

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter.

    Published: 9 Sept 2011
    6.8
    Medium

    CVE-2009-5095

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_ordner parameter.

    Published: 9 Sept 2011
    7.5
    High

    CVE-2009-5094

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL commands via the item parameter.

    Published: 9 Sept 2011
    4.3
    Medium

    CVE-2011-2732

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the spring-security-redirect parameter.

    Published: 9 Sept 2011
    5.1
    Medium

    CVE-2011-2731

    Last Modified: 11 Apr 2025

    Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread.

    Published: 9 Sept 2011
    6.8
    Medium

    CVE-2011-2894

    Last Modified: 11 Apr 2025

    Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrusted code by (1) serializing a java.lang.Proxy instance and using InvocationHandler, or (2) accessing internal AOP interfaces, as demonstrated using deserialization of a DefaultListableBeanFactory instance to execute arbitrary commands via the java.lang.Runtime class.

    Published: 9 Sept 2011
    7.5
    High

    CVE-2011-2730

    Last Modified: 11 Apr 2025

    VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain sensitive information via a (1) name attribute in a (a) spring:hasBindErrors tag; (2) path attribute in a (b) spring:bind or (c) spring:nestedpath tag; (3) arguments, (4) code, (5) text, (6) var, (7) scope, or (8) message attribute in a (d) spring:message or (e) spring:theme tag; or (9) var, (10) scope, or (11) value attribute in a (f) spring:transform tag, aka "Expression Language Injection."

    Published: 9 Sept 2011
    4.3
    Medium

    CVE-2011-3382

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Phorum before 5.2.16 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Sept 2011
    7.5
    High

    CVE-2011-3341

    Last Modified: 11 Apr 2025

    Multiple off-by-one errors in order_cmd.cpp in OpenTTD before 1.1.3 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted CMD_INSERT_ORDER command.

    Published: 8 Sept 2011
    7.5
    High

    CVE-2011-3342

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in OpenTTD before 1.1.3 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors related to (1) NAME, (2) PLYR, (3) CHTS, or (4) AIPL (aka AI config) chunk loading from a savegame.

    Published: 8 Sept 2011
    4.6
    Medium

    CVE-2011-3343

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in OpenTTD before 1.1.3 allow local users to cause a denial of service (daemon crash) or possibly gain privileges via (1) a crafted BMP file with RLE compression or (2) crafted dimensions in a BMP file.

    Published: 8 Sept 2011
    4
    Medium

    CVE-2011-3391

    Last Modified: 11 Apr 2025

    IBM Rational Build Forge 7.1.2 relies on client-side JavaScript code to enforce the EditSecurity permission requirement for the Export Key File function, which allows remote authenticated users to read a key file by removing a disable attribute in the Security sub-menu.

    Published: 8 Sept 2011
    4.3
    Medium

    CVE-2011-3384

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Sage add-on 1.3.10 and earlier for Firefox allows remote attackers to inject arbitrary web script or HTML via a crafted feed, a different vulnerability than CVE-2009-4102.

    Published: 8 Sept 2011
    4.3
    Medium

    CVE-2011-3392

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in control.php in the controlcenter in Phorum before 5.2.17 allows remote attackers to inject arbitrary web script or HTML via the real_name parameter.

    Published: 8 Sept 2011
    6.8
    Medium

    CVE-2011-3381

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Phorum before 5.2.16 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 8 Sept 2011
    7.5
    High

    CVE-2011-3208

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.

    Published: 8 Sept 2011
    4
    Medium

    CVE-2011-3346

    Last Modified: 12 Apr 2025

    Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.

    Published: 7 Sept 2011
    4.3
    Medium

    CVE-2011-3483

    Last Modified: 11 Apr 2025

    Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (application crash) via a malformed capture file that leads to an invalid root tvbuff, related to a "buffer exception handling vulnerability."

    Published: 7 Sept 2011
    4.3
    Medium

    CVE-2011-3484

    Last Modified: 11 Apr 2025

    The unxorFrame function in epan/dissectors/packet-opensafety.c in the OpenSafety dissector in Wireshark 1.6.x before 1.6.2 does not properly validate a certain frame size, which allows remote attackers to cause a denial of service (loop and application crash) via a malformed packet.

    Published: 7 Sept 2011
    4.6
    Medium

    CVE-2011-2925

    Last Modified: 11 Apr 2025

    Cumin in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0 records broker authentication credentials in a log file, which allows local users to bypass authentication and perform unauthorized actions on jobs and message queues via a direct connection to the broker.

    Published: 7 Sept 2011
    4.3
    Medium

    CVE-2011-3482

    Last Modified: 11 Apr 2025

    The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.2 does not initialize a certain structure member, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 7 Sept 2011
    4.3
    Medium

    CVE-2011-3388

    Last Modified: 11 Apr 2025

    Opera before 11.51 allows remote attackers to cause an insecure site to appear secure or trusted via unspecified actions related to Extended Validation and loading content from trusted sources in an unspecified sequence that causes the address field and page information dialog to contain security information based on the trusted site, instead of the insecure site.

    Published: 6 Sept 2011
    4.3
    Medium

    CVE-2011-3389

    Last Modified: 11 Apr 2025

    The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.

    Published: 6 Sept 2011
    7.2
    High

    CVE-2011-2184

    Last Modified: 11 Apr 2025

    The key_replace_session_keyring function in security/keys/process_keys.c in the Linux kernel before 2.6.39.1 does not initialize a certain structure member, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function, a different vulnerability than CVE-2010-2960.

    Published: 6 Sept 2011
    7.5
    High

    CVE-2011-2660

    Last Modified: 11 Apr 2025

    The modify_resolvconf_suse script in the vpnc package before 0.5.1-55.10.1 in SUSE Linux Enterprise Desktop 11 SP1 might allow remote attackers to execute arbitrary commands via a crafted DNS domain name.

    Published: 6 Sept 2011
    3.3
    Low

    CVE-2011-3204

    Last Modified: 11 Apr 2025

    hammerhead.cc in Hammerhead 2.1.4 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/hammer.log (aka the HH_LOG file) or (2) the REPORT_LOG file.

    Published: 6 Sept 2011
    6.9
    Medium

    CVE-2010-4831

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in gdk/win32/gdkinput-win32.c in GTK+ before 2.21.8 allows local users to gain privileges via a Trojan horse Wintab32.dll file in the current working directory.

    Published: 6 Sept 2011
    9.3
    Critical

    CVE-2011-0258

    Last Modified: 11 Apr 2025

    Apple QuickTime before 7.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted image description associated with an mp4v tag in a movie file.

    Published: 6 Sept 2011
    5
    Medium

    CVE-2011-1359

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the administration console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41, 7.0 before 7.0.0.19, and 8.0 before 8.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published: 6 Sept 2011
    9.3
    Critical

    CVE-2011-2654

    Last Modified: 11 Apr 2025

    The RPC implementation in the server in Novell Cloud Manager 1.1.2 before Patch 3 does not properly initialize objects, which allows remote attackers to execute arbitrary code by making RPC calls that leverage incorrect privileges associated with a partially initialized session.

    Published: 6 Sept 2011
    2.1
    Low

    CVE-2011-2700

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the si4713_write_econtrol_string function in drivers/media/radio/si4713-i2c.c in the Linux kernel before 2.6.39.4 on the N900 platform might allow local users to cause a denial of service or have unspecified other impact via a crafted s_ext_ctrls operation with a (1) V4L2_CID_RDS_TX_PS_NAME or (2) V4L2_CID_RDS_TX_RADIO_TEXT control ID.

    Published: 6 Sept 2011
    9.3
    Critical

    CVE-2010-4833

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan horse uxtheme.dll file in the current working directory, a different vulnerability than CVE-2010-4831.

    Published: 6 Sept 2011
    4.3
    Medium

    CVE-2011-3390

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in IBM OpenAdmin Tool (OAT) before 2.72 for Informix allow remote attackers to inject arbitrary web script or HTML via the (1) informixserver, (2) host, or (3) port parameter in a login action.

    Published: 6 Sept 2011
    6.8
    Medium

    CVE-2011-3146

    Last Modified: 11 Apr 2025

    librsvg before 2.34.1 uses the node name to identify the type of node, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference) and possibly execute arbitrary code via a SVG file with a node with the element name starting with "fe," which is misidentified as a RsvgFilterPrimitive.

    Published: 6 Sept 2011
    5
    Medium

    CVE-2011-3207

    Last Modified: 11 Apr 2025

    crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.

    Published: 6 Sept 2011
    5
    Medium

    CVE-2011-3210

    Last Modified: 11 Apr 2025

    The ephemeral ECDH ciphersuite functionality in OpenSSL 0.9.8 through 0.9.8r and 1.0.x before 1.0.0e does not ensure thread safety during processing of handshake messages from clients, which allows remote attackers to cause a denial of service (daemon crash) via out-of-order messages that violate the TLS protocol.

    Published: 6 Sept 2011
    5.8
    Medium

    CVE-2011-1411

    Last Modified: 11 Apr 2025

    Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

    Published: 2 Sept 2011
    4
    Medium

    CVE-2011-3386

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Medtronic Paradigm wireless insulin pump 512, 522, 712, and 722 allows remote attackers to modify the delivery of an insulin bolus dose and cause a denial of service (adverse human health effects) via unspecified vectors involving wireless communications and knowledge of the device's serial number, as demonstrated by Jerome Radcliffe at the Black Hat USA conference in August 2011. NOTE: the vendor has disputed the severity of this issue, saying "we believe the risk of deliberate, malicious, or unauthorized manipulation of medical devices is extremely low... we strongly believe it would be extremely difficult for a third-party to wirelessly tamper with your insulin pump... you would be able to detect tones on the insulin pump that weren't intentionally programmed and could intervene accordingly."

    Published: 2 Sept 2011
    4.3
    Medium

    CVE-2011-3385

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unknown vectors, a different vulnerability than CVE-2006-2307.

    Published: 2 Sept 2011
    4.3
    Medium

    CVE-2009-5086

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Appliance Configuration Manager (ACM) in Juniper IDP 4.1 before 4.1r3 and 4.2 before 4.2r1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Sept 2011
    9.3
    Critical

    CVE-2011-2594

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in KMPlayer 3.0.0.1441, and possibly other versions, allows remote attackers to execute arbitrary code via a playlist (.KPL) file with a long Title field.

    Published: 2 Sept 2011
    7.5
    High

    CVE-2011-2763

    Last Modified: 11 Apr 2025

    The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a modified request to the LSRoom_Remoting.doCommand function in gateway.php.

    Published: 2 Sept 2011
    6.8
    Medium

    CVE-2011-2903

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in tcptrack before 1.4.2 might allow attackers to execute arbitrary code via a long command line argument. NOTE: this is only a vulnerability in limited scenarios in which tcptrack is "configured as a handler for other applications." This issue might not qualify for inclusion in CVE.

    Published: 2 Sept 2011
    10
    Critical

    CVE-2011-0342

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow remote attackers to execute arbitrary code via a long parameter to the (1) Open, (2) Close, or (3) SetCurrentLanguage method.

    Published: 2 Sept 2011
    5
    Medium

    CVE-2011-2762

    Last Modified: 11 Apr 2025

    The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) allows remote attackers to bypass authentication via unspecified data associated with a "true" authentication status, related to AMF data and the LSRoom_Remoting.authenticate function in gateway.php.

    Published: 2 Sept 2011
    4.3
    Medium

    CVE-2011-3132

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Sept 2011
    7.5
    High

    CVE-2011-3134

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to modify data or obtain sensitive information via a crafted URL.

    Published: 2 Sept 2011