CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2011-2646

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename in the list of testdrive modified files.

    Published: 23 Aug 2011
    7.5
    High

    CVE-2011-2647

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted archive name in the list of testdrive modified files.

    Published: 23 Aug 2011
    7.5
    High

    CVE-2011-2648

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a filter in a modified file.

    Published: 23 Aug 2011
    7.5
    High

    CVE-2011-2649

    Last Modified: 11 Apr 2025

    Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.

    Published: 23 Aug 2011
    4.3
    Medium

    CVE-2011-2650

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted pattern name that is included in an RPM info display.

    Published: 23 Aug 2011
    7.9
    High

    CVE-2011-2735

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in EMC AutoStart 5.3.x and 5.4.x before 5.4.1 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by sending a crafted message over TCP.

    Published: 23 Aug 2011
    9.3
    Critical

    CVE-2011-2225

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to have an unknown impact via a crafted directory pathname that is inserted into config.sh.

    Published: 23 Aug 2011
    7.5
    High

    CVE-2011-2651

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the file browser in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename.

    Published: 23 Aug 2011
    4.3
    Medium

    CVE-2011-2652

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted archive file list that is used in an overlay file.

    Published: 23 Aug 2011
    3.8
    Low

    CVE-2011-3145

    Last Modified: 21 Nov 2024

    When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of the user running mount.ecryptfs_private.

    Published: 23 Aug 2011
    8.8
    High

    CVE-2011-3191

    Last Modified: 11 Apr 2025

    Integer signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel before 3.1 allows remote CIFS servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large length value in a response to a read request for a directory.

    Published: 23 Aug 2011
    7.5
    High

    CVE-2011-2821

    Last Modified: 11 Apr 2025

    Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.

    Published: 22 Aug 2011
    4.3
    Medium

    CVE-2011-3184

    Last Modified: 11 Apr 2025

    The msn_httpconn_parse_data function in httpconn.c in the MSN protocol plugin in libpurple in Pidgin before 2.10.0 does not properly handle HTTP 100 responses, which allows remote attackers to cause a denial of service (incorrect memory access and application crash) via vectors involving a crafted server message.

    Published: 20 Aug 2011
    7.5
    High

    CVE-2011-3190

    Last Modified: 11 Apr 2025

    Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.

    Published: 20 Aug 2011
    7.8
    High

    CVE-2011-3192

    Last Modified: 11 Apr 2025

    The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.

    Published: 20 Aug 2011
    6.8
    Medium

    CVE-2011-1341

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Aimluck Aipo before 4.0.4.0, and Aipo for ASP before 4.0.4.0, allows remote attackers to hijack the authentication of administrators for requests that modify data.

    Published: 19 Aug 2011
    5
    Medium

    CVE-2011-3265

    Last Modified: 11 Apr 2025

    popup.php in Zabbix before 1.8.7 allows remote attackers to read the contents of arbitrary database tables via a modified srctbl parameter.

    Published: 19 Aug 2011
    7.5
    High

    CVE-2011-1342

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Aimluck Aipo before 5.1.1, and Aipo for ASP before 5.1.1, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Aug 2011
    5
    Medium

    CVE-2011-3263

    Last Modified: 11 Apr 2025

    zabbix_agentd in Zabbix before 1.8.6 and 1.9.x before 1.9.4 allows context-dependent attackers to cause a denial of service (CPU consumption) by executing the vfs.file.cksum command for a special device, as demonstrated by the /dev/urandom device.

    Published: 19 Aug 2011
    10
    Critical

    CVE-2011-0547

    Last Modified: 11 Apr 2025

    Multiple integer overflows in vxsvc.exe in the Veritas Enterprise Administrator service in Symantec Veritas Storage Foundation 5.1 and earlier, Veritas Storage Foundation Cluster File System (SFCFS) 5.1 and earlier, Veritas Storage Foundation Cluster File System Enterprise for Oracle RAC (SFCFSORAC) 5.1 and earlier, Veritas Dynamic Multi-Pathing (DMP) 5.1, and NetBackup PureDisk 6.5.x through 6.6.1.x allow remote attackers to execute arbitrary code via (1) a crafted Unicode string, related to the vxveautil.value_binary_unpack function; (2) a crafted ASCII string, related to the vxveautil.value_binary_unpack function; or (3) a crafted value, related to the vxveautil.kv_binary_unpack function, leading to a buffer overflow.

    Published: 19 Aug 2011
    4.3
    Medium

    CVE-2011-2904

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in acknow.php in Zabbix before 1.8.6 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter.

    Published: 19 Aug 2011
    5
    Medium

    CVE-2011-3264

    Last Modified: 11 Apr 2025

    Zabbix before 1.8.6 allows remote attackers to obtain sensitive information via an invalid srcfld2 parameter to popup.php, which reveals the installation path in an error message.

    Published: 19 Aug 2011
    Unknown

    CVE-2011-2810

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-0253. Reason: This candidate is a reservation duplicate of CVE-2011-0253. Notes: All CVE users should reference CVE-2011-0253 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 19 Aug 2011
    4.3
    Medium

    CVE-2011-2410

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Aug 2011
    Unknown

    CVE-2011-3258

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Aug 2011
    5
    Medium

    CVE-2011-3182

    Last Modified: 11 Apr 2025

    PHP before 5.3.7 does not properly check the return values of the malloc, calloc, and realloc library functions, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger a buffer overflow by leveraging the ability to provide an arbitrary value for a function argument, related to (1) ext/curl/interface.c, (2) ext/date/lib/parse_date.c, (3) ext/date/lib/parse_iso_intervals.c, (4) ext/date/lib/parse_tz.c, (5) ext/date/lib/timelib.c, (6) ext/pdo_odbc/pdo_odbc.c, (7) ext/reflection/php_reflection.c, (8) ext/soap/php_sdl.c, (9) ext/xmlrpc/libxmlrpc/base64.c, (10) TSRM/tsrm_win32.c, and (11) the strtotime function.

    Published: 19 Aug 2011
    Unknown

    CVE-2011-3240

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 19 Aug 2011
    9.3
    Critical

    CVE-2011-2945

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted SIPR stream.

    Published: 18 Aug 2011
    10
    Critical

    CVE-2011-2946

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in an ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 18 Aug 2011
    9.3
    Critical

    CVE-2011-2948

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, RealPlayer Enterprise 2.0 through 2.1.5, and Mac RealPlayer 12.0.0.1569 do not properly handle DEFINEFONT fields in SWF files, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted file.

    Published: 18 Aug 2011
    9.3
    Critical

    CVE-2011-2949

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via crafted ID3v2 tags in an MP3 file.

    Published: 18 Aug 2011
    9.3
    Critical

    CVE-2011-2950

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted QCP file.

    Published: 18 Aug 2011
    9.3
    Critical

    CVE-2011-2951

    Last Modified: 11 Apr 2025

    Buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer 12.0.0.1569 allows remote attackers to execute arbitrary code via a crafted raw_data_frame field in an AAC file.

    Published: 18 Aug 2011
    9.3
    Critical

    CVE-2011-2952

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via vectors related to a dialog box.

    Published: 18 Aug 2011
    10
    Critical

    CVE-2011-2953

    Last Modified: 11 Apr 2025

    An unspecified ActiveX control in the browser plugin in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via unknown vectors, related to an out-of-bounds condition.

    Published: 18 Aug 2011
    9.3
    Critical

    CVE-2011-2954

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the AutoUpdate feature in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5, when an Embedded RealPlayer is used, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 18 Aug 2011
    7.5
    High

    CVE-2011-2733

    Last Modified: 11 Apr 2025

    EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not prevent reuse of authentication information during a session, which allows remote authenticated users to bypass intended access restrictions via vectors related to knowledge of the originally used authentication information and unspecified other session information.

    Published: 18 Aug 2011
    4.3
    Medium

    CVE-2011-2947

    Last Modified: 11 Apr 2025

    Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document.

    Published: 18 Aug 2011
    9.3
    Critical

    CVE-2011-2955

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5, when an Embedded RealPlayer is used, allows remote attackers to execute arbitrary code via vectors related to a modal dialog.

    Published: 18 Aug 2011
    7.8
    High

    CVE-2011-1624

    Last Modified: 11 Apr 2025

    Cisco IOS 12.2(58)SE, when a login banner is configured, allows remote attackers to cause a denial of service (device reload) by establishing two SSH2 sessions, aka Bug ID CSCto62631.

    Published: 18 Aug 2011
    7.2
    High

    CVE-2011-2980

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in the ThinkPadSensor::Startup function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, allows local users to gain privileges by leveraging write access in an unspecified directory to place a Trojan horse DLL that is loaded into the running Firefox process.

    Published: 18 Aug 2011
    10
    Critical

    CVE-2011-2985

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 18 Aug 2011
    10
    Critical

    CVE-2011-2987

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Almost Native Graphics Layer Engine (ANGLE), as used in the WebGL implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products might allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 18 Aug 2011
    10
    Critical

    CVE-2011-2989

    Last Modified: 11 Apr 2025

    The browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6, and possibly other products does not properly implement WebGL, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

    Published: 18 Aug 2011
    5
    Medium

    CVE-2011-2990

    Last Modified: 11 Apr 2025

    The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not remove proxy-authorization credentials from the listed request headers, which allows attackers to obtain sensitive information by reading a report, related to incorrect host resolution that occurs with certain redirects.

    Published: 18 Aug 2011
    10
    Critical

    CVE-2011-2991

    Last Modified: 11 Apr 2025

    The browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6, and possibly other products does not properly implement JavaScript, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

    Published: 18 Aug 2011
    10
    Critical

    CVE-2011-2992

    Last Modified: 11 Apr 2025

    The Ogg reader in the browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6, and possibly other products allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

    Published: 18 Aug 2011
    5
    Medium

    CVE-2011-2986

    Last Modified: 11 Apr 2025

    Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas.

    Published: 18 Aug 2011
    5.4
    Medium

    CVE-2011-1625

    Last Modified: 11 Apr 2025

    Cisco IOS 12.2, 12.3, 12.4, 15.0, and 15.1, when the data-link switching (DLSw) feature is configured, allows remote attackers to cause a denial of service (device crash) by sending a sequence of malformed packets and leveraging a "narrow timing window," aka Bug ID CSCtf74999, a different vulnerability than CVE-2007-0199, CVE-2008-1152, and CVE-2009-0629.

    Published: 18 Aug 2011
    10
    Critical

    CVE-2011-2988

    Last Modified: 11 Apr 2025

    Buffer overflow in an unspecified string class in the WebGL shader implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long source-code block for a shader.

    Published: 18 Aug 2011