CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2011-2993

    Last Modified: 11 Apr 2025

    The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not prevent calls from unsigned JavaScript code to signed code, which allows remote attackers to bypass the Same Origin Policy and gain privileges via a crafted web site, a different vulnerability than CVE-2008-2801.

    Published: 18 Aug 2011
    9.3
    Critical

    CVE-2011-2940

    Last Modified: 11 Apr 2025

    stunnel 4.40 and 4.41 might allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

    Published: 18 Aug 2011
    5
    Medium

    CVE-2011-3267

    Last Modified: 11 Apr 2025

    PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 18 Aug 2011
    4.3
    Medium

    CVE-2011-3189

    Last Modified: 11 Apr 2025

    The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.

    Published: 17 Aug 2011
    10
    Critical

    CVE-2011-3268

    Last Modified: 11 Apr 2025

    Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

    Published: 17 Aug 2011
    10
    Critical

    CVE-2011-3142

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute arbitrary code via a long second argument to the ValidateUser method.

    Published: 16 Aug 2011
    4.3
    Medium

    CVE-2011-3144

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Aug 2011
    9.3
    Critical

    CVE-2011-3141

    Last Modified: 11 Apr 2025

    Buffer overflow in the InBatch BatchField ActiveX control for Invensys Wonderware InBatch 8.1 SP1, 9.0, and 9.0 SP1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

    Published: 16 Aug 2011
    10
    Critical

    CVE-2011-3143

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified long strings that trigger heap memory corruption.

    Published: 16 Aug 2011
    10
    Critical

    CVE-2011-2378

    Last Modified: 11 Apr 2025

    The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey 2.x, and possibly other products does not properly handle DOM objects, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to dereferencing of a "dangling pointer."

    Published: 16 Aug 2011
    9.3
    Critical

    CVE-2011-2981

    Last Modified: 11 Apr 2025

    The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.

    Published: 16 Aug 2011
    10
    Critical

    CVE-2011-2982

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 16 Aug 2011
    4.3
    Medium

    CVE-2011-2983

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products does not properly handle the RegExp.input property, which allows remote attackers to bypass the Same Origin Policy and read data from a different domain via a crafted web site, possibly related to a use-after-free.

    Published: 16 Aug 2011
    10
    Critical

    CVE-2011-2984

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.

    Published: 16 Aug 2011
    10
    Critical

    CVE-2011-0084

    Last Modified: 11 Apr 2025

    The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."

    Published: 16 Aug 2011
    9.3
    Critical

    CVE-2011-0256

    Last Modified: 11 Apr 2025

    Integer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted track run atoms in a QuickTime movie file.

    Published: 15 Aug 2011
    9.3
    Critical

    CVE-2011-0257

    Last Modified: 11 Apr 2025

    Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PnSize opcode in a PICT file that triggers a stack-based buffer overflow.

    Published: 15 Aug 2011
    5
    Medium

    CVE-2011-3140

    Last Modified: 11 Apr 2025

    IBM Web Application Firewall, as used on the G400 IPS-G400-IB-1 and GX4004 IPS-GX4004-IB-2 appliances with update 31.030, does not properly handle query strings with multiple instances of the same parameter, which allows remote attackers to bypass intended intrusion prevention by dividing a dangerous parameter value into substrings, as demonstrated by a SQL statement that is split across multiple iid parameters and then sent to a .aspx file on an IIS web server.

    Published: 15 Aug 2011
    5
    Medium

    CVE-2011-0527

    Last Modified: 11 Apr 2025

    VMware vFabric tc Server (aka SpringSource tc Server) 2.0.x before 2.0.6.RELEASE and 2.1.x before 2.1.2.RELEASE accepts obfuscated passwords during JMX authentication, which makes it easier for context-dependent attackers to obtain access by leveraging an ability to read stored passwords.

    Published: 15 Aug 2011
    7.5
    High

    CVE-2011-2907

    Last Modified: 11 Apr 2025

    Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 3.0.1 and earlier allows remote attackers to bypass host-based authentication and submit arbitrary jobs via a modified PBS_O_HOST variable to the qsub program.

    Published: 15 Aug 2011
    5
    Medium

    CVE-2011-3011

    Last Modified: 11 Apr 2025

    BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, via unspecified vectors.

    Published: 15 Aug 2011
    4.3
    Medium

    CVE-2011-0550

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allow remote attackers to inject arbitrary web script or HTML via (1) the token parameter to portal/Help.jsp or (2) the URI in a console/apps/sepm request.

    Published: 15 Aug 2011
    6.8
    Medium

    CVE-2011-0551

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

    Published: 15 Aug 2011
    4.3
    Medium

    CVE-2011-2357

    Last Modified: 11 Apr 2025

    Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs to be opened, then loading a URI to the targeted domain into the current tab, or (2) making two startActivity function calls beginning with the targeted domain's URI followed by the malicious Javascript while the UI focus is still associated with the targeted domain.

    Published: 12 Aug 2011
    5
    Medium

    CVE-2008-7299

    Last Modified: 11 Apr 2025

    IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers to spoof assertions via vectors related to the Issuer field.

    Published: 12 Aug 2011
    6.8
    Medium

    CVE-2009-5083

    Last Modified: 11 Apr 2025

    IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login rejection upon receiving an OP-Identifier from an OpenID provider, which allows remote attackers to bypass authentication via unspecified vectors.

    Published: 12 Aug 2011
    1.9
    Low

    CVE-2009-5084

    Last Modified: 11 Apr 2025

    IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when com.tivoli.am.fim.infocard.delegates.InfoCardSTSDelegate tracing is enabled, creates a cleartext log entry containing a password, which might allow local users to obtain sensitive information by reading the log data.

    Published: 12 Aug 2011
    10
    Critical

    CVE-2011-3135

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Runtime in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors.

    Published: 12 Aug 2011
    10
    Critical

    CVE-2011-3136

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors, aka APAR IV03048.

    Published: 12 Aug 2011
    10
    Critical

    CVE-2011-3137

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors, aka APAR IV03050.

    Published: 12 Aug 2011
    2.6
    Low

    CVE-2009-5085

    Last Modified: 11 Apr 2025

    IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID provider, does not delete the site information cookie in response to a user's deletion of a relying-party trust entry, which allows user-assisted remote attackers to bypass intended trust restrictions via vectors that trigger absence of the consent-to-authenticate page.

    Published: 12 Aug 2011
    5
    Medium

    CVE-2011-3138

    Last Modified: 11 Apr 2025

    The LTPA STS module support implementation in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 relies on a static instance of a Java Development Kit (JDK) class, which might allow attackers to bypass LTPA token signature verification by leveraging lack of thread safety.

    Published: 12 Aug 2011
    5
    Medium

    CVE-2011-2729

    Last Modified: 11 Apr 2025

    native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

    Published: 12 Aug 2011
    4.6
    Medium

    CVE-2011-2481

    Last Modified: 11 Apr 2025

    Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. NOTE: this vulnerability exists because of a CVE-2009-0783 regression.

    Published: 12 Aug 2011
    4.6
    Medium

    CVE-2011-3131

    Last Modified: 11 Apr 2025

    Xen 4.1.1 and earlier allows local guest OS kernels with control of a PCI[E] device to cause a denial of service (CPU consumption and host hang) via many crafted DMA requests that are denied by the IOMMU, which triggers a livelock.

    Published: 12 Aug 2011
    10
    Critical

    CVE-2010-4308

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-4309.

    Published: 11 Aug 2011
    10
    Critical

    CVE-2010-4309

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-4308.

    Published: 11 Aug 2011
    5
    Medium

    CVE-2011-2132

    Last Modified: 11 Apr 2025

    Adobe Flash Media Server (FMS) before 3.5.7, and 4.x before 4.0.3, allows attackers to cause a denial of service (memory corruption) via unspecified vectors.

    Published: 11 Aug 2011
    4.3
    Medium

    CVE-2011-2133

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 8 and 9 before 9.0.1.262, and RoboHelp Server 8 and 9, allows remote attackers to inject arbitrary web script or HTML via the URI, related to template_stock/whutils.js.

    Published: 11 Aug 2011
    7.5
    High

    CVE-2011-2404

    Last Modified: 11 Apr 2025

    A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via unspecified vectors, a different vulnerability than CVE-2011-4786 and CVE-2011-4787.

    Published: 11 Aug 2011
    3.5
    Low

    CVE-2011-2406

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Aug 2011
    6.4
    Medium

    CVE-2011-2407

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP OpenView Performance Insight 5.3, 5.31, 5.4, 5.41, 5.41.001, and 5.41.002 allows remote attackers to obtain access via unknown vectors.

    Published: 11 Aug 2011
    4.3
    Medium

    CVE-2011-2408

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Contacts application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Aug 2011
    4.3
    Medium

    CVE-2011-2409

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Calendar application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Aug 2011
    10
    Critical

    CVE-2011-2419

    Last Modified: 11 Apr 2025

    IML32.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 11 Aug 2011
    10
    Critical

    CVE-2011-2420

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 11 Aug 2011
    9.3
    Critical

    CVE-2011-2421

    Last Modified: 11 Apr 2025

    Dirapi.dll in Adobe Shockwave Player before 11.6.1.629 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir media file.

    Published: 11 Aug 2011
    10
    Critical

    CVE-2011-2423

    Last Modified: 11 Apr 2025

    msvcr90.dll in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 11 Aug 2011
    4.3
    Medium

    CVE-2011-1357

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in agentDetect.jsp in the web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 before 6.3.0.5, 7.0 before 7.0.0.5, and 7.5 before 7.5.0.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

    Published: 11 Aug 2011
    9.3
    Critical

    CVE-2011-2131

    Last Modified: 11 Apr 2025

    Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GIF file.

    Published: 11 Aug 2011