CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2011-3133

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 2 Sept 2011
    5
    Medium

    CVE-2011-3200

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 through 5.8.4 might allow remote attackers to cause a denial of service (application exit) via a long TAG in a legacy syslog message.

    Published: 1 Sept 2011
    7.8
    High

    CVE-2011-2577

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs, when using software versions before TC 4.0.0 or F9.1, allows remote attackers to cause a denial of service (crash) via a crafted SIP packet to port 5060 or 5061, aka Bug ID CSCtq46500.

    Published: 31 Aug 2011
    4.3
    Medium

    CVE-2012-1154

    Last Modified: 11 Apr 2025

    mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.

    Published: 31 Aug 2011
    7.5
    High

    CVE-2011-2482

    Last Modified: 11 Apr 2025

    A certain Red Hat patch to the sctp_sock_migrate function in net/sctp/socket.c in the Linux kernel before 2.6.21, as used in Red Hat Enterprise Linux (RHEL) 5, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) via a crafted SCTP packet.

    Published: 30 Aug 2011
    5.5
    Medium

    CVE-2011-2519

    Last Modified: 11 Apr 2025

    Xen in the Linux kernel, when running a guest on a host without hardware assisted paging (HAP), allows guest users to cause a denial of service (invalid pointer dereference and hypervisor crash) via the SAHF instruction.

    Published: 30 Aug 2011
    5.5
    Medium

    CVE-2011-2901

    Last Modified: 11 Apr 2025

    Off-by-one error in the __addr_ok macro in Xen 3.3 and earlier allows local 64 bit PV guest administrators to cause a denial of service (host crash) via unspecified hypercalls that ignore virtual-address bits.

    Published: 30 Aug 2011
    7.5
    High

    CVE-2011-0228

    Last Modified: 11 Apr 2025

    The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which allows man-in-the-middle attackers to spoof an SSL server by using a non-CA certificate to sign a certificate for an arbitrary domain.

    Published: 29 Aug 2011
    10
    Critical

    CVE-2011-2555

    Last Modified: 11 Apr 2025

    Cisco TelePresence Recording Server 1.7.2.x before 1.7.2.1 has a default password for the root administrator account, which makes it easier for remote attackers to modify the configuration via an SSH session, aka Bug ID CSCtr76182.

    Published: 29 Aug 2011
    7.5
    High

    CVE-2011-2930

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the quote_table_name method in the ActiveRecord adapters in activerecord/lib/active_record/connection_adapters/ in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allow remote attackers to execute arbitrary SQL commands via a crafted column name.

    Published: 29 Aug 2011
    4.3
    Medium

    CVE-2011-2932

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails 2.x before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a malformed Unicode string, related to a "UTF-8 escaping vulnerability."

    Published: 29 Aug 2011
    4.3
    Medium

    CVE-2011-3186

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.

    Published: 29 Aug 2011
    4.3
    Medium

    CVE-2011-3187

    Last Modified: 11 Apr 2025

    The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.

    Published: 29 Aug 2011
    5
    Medium

    CVE-2011-2929

    Last Modified: 11 Apr 2025

    The template selection functionality in actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.10 and 3.1.x before 3.1.0.rc6 does not properly handle glob characters, which allows remote attackers to render arbitrary views via a crafted URL, related to a "filter skipping vulnerability."

    Published: 29 Aug 2011
    4.3
    Medium

    CVE-2011-2931

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the strip_tags helper in actionpack/lib/action_controller/vendor/html-scanner/html/node.rb in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a tag with an invalid name.

    Published: 29 Aug 2011
    4.3
    Medium

    CVE-2011-3181

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Tracking feature in phpMyAdmin 3.3.x before 3.3.10.4 and 3.4.x before 3.4.4 allow remote attackers to inject arbitrary web script or HTML via a (1) table name, (2) column name, or (3) index name.

    Published: 29 Aug 2011
    9.3
    Critical

    CVE-2011-3185

    Last Modified: 11 Apr 2025

    gtkutils.c in Pidgin before 2.10.0 on Windows allows user-assisted remote attackers to execute arbitrary programs via a file: URL in a message.

    Published: 29 Aug 2011
    4.9
    Medium

    CVE-2011-2928

    Last Modified: 11 Apr 2025

    The befs_follow_link function in fs/befs/linuxvfs.c in the Linux kernel before 3.1-rc3 does not validate the length attribute of long symlinks, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) by accessing a long symlink on a malformed Be filesystem.

    Published: 29 Aug 2011
    7.8
    High

    CVE-2011-2560

    Last Modified: 11 Apr 2025

    The Packet Capture Service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x does not properly handle idle TCP connections, which allows remote attackers to cause a denial of service (memory consumption and restart) by making many connections, aka Bug ID CSCtf97162.

    Published: 29 Aug 2011
    7.8
    High

    CVE-2011-2562

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (service outage) via a SIP INVITE message, aka Bug ID CSCth43256.

    Published: 29 Aug 2011
    7.8
    High

    CVE-2011-2563

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 8.x before 8.5(1) and Cisco Intercompany Media Engine 8.x before 8.5(1) allows remote attackers to cause a denial of service (device reload) via crafted SAF packets, aka Bug ID CSCth26669.

    Published: 29 Aug 2011
    7.8
    High

    CVE-2011-2564

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 8.x before 8.5(1) and Cisco Intercompany Media Engine 8.x before 8.5(1) allows remote attackers to cause a denial of service (device reload) via crafted SAF packets, aka Bug ID CSCth19417.

    Published: 29 Aug 2011
    2.6
    Low

    CVE-2011-2712

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 29 Aug 2011
    4
    Medium

    CVE-2011-2746

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Kernel/Modules/AdminPackageManager.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.x before 2.4.11 and 3.x before 3.0.10 allows remote authenticated administrators to read arbitrary files via unknown vectors.

    Published: 29 Aug 2011
    10
    Critical

    CVE-2011-2806

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.215 on Windows does not properly handle vertex data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 29 Aug 2011
    10
    Critical

    CVE-2011-2822

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.215 on Windows does not properly parse URLs located on the command line, which has unspecified impact and attack vectors.

    Published: 29 Aug 2011
    7.5
    High

    CVE-2011-2824

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving counter nodes.

    Published: 29 Aug 2011
    9.3
    Critical

    CVE-2011-2825

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving custom fonts.

    Published: 29 Aug 2011
    7.5
    High

    CVE-2011-2826

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.215 allows remote attackers to bypass the Same Origin Policy via vectors related to empty origins.

    Published: 29 Aug 2011
    7.5
    High

    CVE-2011-2827

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to text searching.

    Published: 29 Aug 2011
    7.5
    High

    CVE-2011-2828

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.

    Published: 29 Aug 2011
    7.5
    High

    CVE-2011-2829

    Last Modified: 11 Apr 2025

    Integer overflow in Google Chrome before 13.0.782.215 on 32-bit platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving uniform arrays.

    Published: 29 Aug 2011
    7.5
    High

    CVE-2011-2839

    Last Modified: 11 Apr 2025

    The PDF implementation in Google Chrome before 13.0.782.215 on Linux does not properly use the memset library function, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 29 Aug 2011
    10
    Critical

    CVE-2011-1643

    Last Modified: 11 Apr 2025

    Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8.0, and 8.5 before 8.5(1)su2 and Cisco Unified Presence Server 6.x, 7.x, 8.0, and 8.5 before 8.5xnr allow remote attackers to read database data by connecting to a query interface through an SSL session, aka Bug IDs CSCti81574, CSCto63060, CSCto72183, and CSCto73833.

    Published: 29 Aug 2011
    7.1
    High

    CVE-2011-2561

    Last Modified: 11 Apr 2025

    The SIP process in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(5b)su4 and 8.x before 8.0(1) does not properly handle SDP data within a SIP call in certain situations related to use of the g729ar8 codec for a Media Termination Point (MTP), which allows remote attackers to cause a denial of service (service outage) via a crafted call, aka Bug ID CSCtc61990.

    Published: 29 Aug 2011
    7.5
    High

    CVE-2011-2823

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a line box.

    Published: 29 Aug 2011
    6.8
    Medium

    CVE-2011-3205

    Last Modified: 11 Apr 2025

    Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response. NOTE: This issue exists because of a CVE-2005-0094 regression.

    Published: 28 Aug 2011
    5
    Medium

    CVE-2011-2737

    Last Modified: 11 Apr 2025

    RSA enVision 3.x and 4.x before 4 SP4 P3 allows remote attackers to read arbitrary files via unspecified vectors, related to an "arbitrary file retrieval vulnerability."

    Published: 25 Aug 2011
    5
    Medium

    CVE-2011-2736

    Last Modified: 11 Apr 2025

    RSA enVision 4.x before 4 SP4 P3 places cleartext administrative credentials in Task Escalation e-mail messages, which allows remote attackers to obtain sensitive information by sniffing the network or leveraging access to a recipient mailbox.

    Published: 25 Aug 2011
    5.5
    Medium

    CVE-2011-4594

    Last Modified: 11 Apr 2025

    The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted use of the sendmmsg system call, leading to an incorrect pointer dereference.

    Published: 25 Aug 2011
    4.3
    Medium

    CVE-2011-3201

    Last Modified: 11 Apr 2025

    GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.

    Published: 25 Aug 2011
    4.3
    Medium

    CVE-2010-4827

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to inject arbitrary web script or HTML via the M_NAME parameter. NOTE: some of these details are obtained from third party information.

    Published: 24 Aug 2011
    4.3
    Medium

    CVE-2010-4828

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) 10.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to MapView.aspx; NetObject parameter to (2) NodeDetails.aspx and (3) InterfaceDetails.aspx; and the (4) ChartName parameter to CustomChart.aspx.

    Published: 24 Aug 2011
    7.5
    High

    CVE-2010-4829

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in processview.asp in Techno Dreams (T-Dreams) Cars Ads Package 2.0 allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Published: 24 Aug 2011
    7.5
    High

    CVE-2010-4830

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Resumes/TD_RESUME_Indlist.asp in Techno Dreams (T-Dreams) Job Career Package 3.0 allows remote attackers to execute arbitrary SQL commands via the z_Residency parameter.

    Published: 24 Aug 2011
    7.5
    High

    CVE-2010-4826

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to execute arbitrary SQL commands via the M_NAME parameter. NOTE: some of these details are obtained from third party information.

    Published: 24 Aug 2011
    4.3
    Medium

    CVE-2010-4825

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in magpie_debug.php in the Twitter Feed plugin (wp-twitter-feed) 0.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 24 Aug 2011
    4.3
    Medium

    CVE-2011-2226

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a pattern listing.

    Published: 23 Aug 2011
    4.3
    Medium

    CVE-2011-2644

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info display.

    Published: 23 Aug 2011
    7.5
    High

    CVE-2011-2645

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename for a custom RPM.

    Published: 23 Aug 2011