CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2011-2405

    Last Modified: 11 Apr 2025

    The HP ProLiant SL Advanced Power Manager (SL-APM) with firmware before 1.20 does not properly validate users, which allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 11 Aug 2011
    10
    Critical

    CVE-2011-2422

    Last Modified: 11 Apr 2025

    Textra.x32 in Adobe Shockwave Player before 11.6.1.629 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 11 Aug 2011
    5
    Medium

    CVE-2011-1970

    Last Modified: 11 Apr 2025

    The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."

    Published: 10 Aug 2011
    7.6
    High

    CVE-2011-1257

    Last Modified: 11 Apr 2025

    Race condition in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors involving access to an object, aka "Window Open Race Condition Vulnerability."

    Published: 10 Aug 2011
    4.3
    Medium

    CVE-2011-1263

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the logon page in Remote Desktop Web Access (RD Web Access) in Microsoft Windows Server 2008 R2 and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "Remote Desktop Web Access Vulnerability."

    Published: 10 Aug 2011
    7.8
    High

    CVE-2011-1871

    Last Modified: 11 Apr 2025

    Tcpip.sys in the TCP/IP stack in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a series of crafted ICMP messages, aka "ICMP Denial of Service Vulnerability."

    Published: 10 Aug 2011
    4.3
    Medium

    CVE-2011-1960

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not properly implement JavaScript event handlers, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Event Handlers Information Disclosure Vulnerability."

    Published: 10 Aug 2011
    9.3
    Critical

    CVE-2011-1961

    Last Modified: 11 Apr 2025

    The telnet URI handler in Microsoft Internet Explorer 6 through 9 does not properly launch the handler application, which allows remote attackers to execute arbitrary programs via a crafted web site, aka "Telnet Handler Remote Code Execution Vulnerability."

    Published: 10 Aug 2011
    4.3
    Medium

    CVE-2011-1962

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not properly handle unspecified character sequences, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers "inactive filtering," aka "Shift JIS Character Encoding Vulnerability."

    Published: 10 Aug 2011
    7.1
    High

    CVE-2011-1965

    Last Modified: 11 Apr 2025

    Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server, aka "TCP/IP QOS Denial of Service Vulnerability."

    Published: 10 Aug 2011
    10
    Critical

    CVE-2011-1966

    Last Modified: 11 Apr 2025

    The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, aka "DNS NAPTR Query Vulnerability."

    Published: 10 Aug 2011
    4.7
    Medium

    CVE-2011-1971

    Last Modified: 11 Apr 2025

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse file metadata, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Metadata Parsing DOS Vulnerability."

    Published: 10 Aug 2011
    9.3
    Critical

    CVE-2011-1972

    Last Modified: 11 Apr 2025

    Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream Release RCE Vulnerability."

    Published: 10 Aug 2011
    9.3
    Critical

    CVE-2011-1975

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in the Data Access Tracing component in Windows Data Access Components (Windows DAC) 6.0 in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an Excel .xlsx file, aka "Data Access Components Insecure Library Loading Vulnerability."

    Published: 10 Aug 2011
    4.3
    Medium

    CVE-2011-1976

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XSS Vulnerability."

    Published: 10 Aug 2011
    9.3
    Critical

    CVE-2011-1979

    Last Modified: 11 Apr 2025

    Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."

    Published: 10 Aug 2011
    5
    Medium

    CVE-2011-3126

    Last Modified: 11 Apr 2025

    WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.

    Published: 10 Aug 2011
    5
    Medium

    CVE-2011-3128

    Last Modified: 11 Apr 2025

    WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php.

    Published: 10 Aug 2011
    9.3
    Critical

    CVE-2011-3129

    Last Modified: 11 Apr 2025

    The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.

    Published: 10 Aug 2011
    7.5
    High

    CVE-2011-3130

    Last Modified: 11 Apr 2025

    wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.

    Published: 10 Aug 2011
    9.3
    Critical

    CVE-2011-1964

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Style Object Memory Corruption Vulnerability."

    Published: 10 Aug 2011
    7.2
    High

    CVE-2011-1967

    Last Modified: 11 Apr 2025

    Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Vulnerability."

    Published: 10 Aug 2011
    7.2
    High

    CVE-2011-1974

    Last Modified: 11 Apr 2025

    NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI Elevation of Privilege Vulnerability."

    Published: 10 Aug 2011
    4.3
    Medium

    CVE-2011-1977

    Last Modified: 11 Apr 2025

    The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP request, aka "Chart Control Information Disclosure Vulnerability."

    Published: 10 Aug 2011
    4.3
    Medium

    CVE-2011-1978

    Last Modified: 11 Apr 2025

    Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Socket Restriction Bypass Vulnerability."

    Published: 10 Aug 2011
    5.8
    Medium

    CVE-2011-3127

    Last Modified: 11 Apr 2025

    WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

    Published: 10 Aug 2011
    9.3
    Critical

    CVE-2011-1963

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "XSLT Memory Corruption Vulnerability."

    Published: 10 Aug 2011
    7.1
    High

    CVE-2011-1968

    Last Modified: 11 Apr 2025

    The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets in memory, which allows remote attackers to cause a denial of service (reboot) by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, as exploited in the wild in 2011, aka "Remote Desktop Protocol Vulnerability."

    Published: 10 Aug 2011
    10
    Critical

    CVE-2011-3125

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hardening."

    Published: 10 Aug 2011
    10
    Critical

    CVE-2011-3122

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."

    Published: 10 Aug 2011
    7.2
    High

    CVE-2011-3124

    Last Modified: 11 Apr 2025

    IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns incorrect ownership to unspecified files, which allows local users to gain privileges via unknown vectors.

    Published: 10 Aug 2011
    6.8
    Medium

    CVE-2011-3006

    Last Modified: 11 Apr 2025

    The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to bypass the MyASUtil.SecureObjectFactory.CreateSecureObject domain execution policy using a cross-site scripting (XSS) attack, execute arbitrary code using the MyASUtil.InstallInfo.RunUserProgram function, and possibly conduct other unspecified attacks.

    Published: 10 Aug 2011
    6.8
    Medium

    CVE-2011-3007

    Last Modified: 11 Apr 2025

    The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files by specifying an arbitrary filename in the MyCioScan.Scan.ReportFile parameter, as demonstrated by injecting script into a log file and executing arbitrary code using the MyCioScan.Scan.Start method.

    Published: 10 Aug 2011
    7.2
    High

    CVE-2011-3123

    Last Modified: 11 Apr 2025

    IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.

    Published: 10 Aug 2011
    7.8
    High

    CVE-2011-2748

    Last Modified: 11 Apr 2025

    The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted DHCP packet.

    Published: 10 Aug 2011
    7.8
    High

    CVE-2011-2749

    Last Modified: 11 Apr 2025

    The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet.

    Published: 10 Aug 2011
    5.1
    Medium

    CVE-2011-2896

    Last Modified: 11 Apr 2025

    The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.

    Published: 10 Aug 2011
    9.3
    Critical

    CVE-2011-2895

    Last Modified: 11 Apr 2025

    The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.

    Published: 10 Aug 2011
    5
    Medium

    CVE-2011-2221

    Last Modified: 11 Apr 2025

    The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to bypass WebAdmin authentication and obtain sensitive GroupWise information via unspecified vectors.

    Published: 9 Aug 2011
    5
    Medium

    CVE-2011-2223

    Last Modified: 11 Apr 2025

    The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 9 Aug 2011
    4.3
    Medium

    CVE-2011-2222

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 9 Aug 2011
    9.3
    Critical

    CVE-2011-2590

    Last Modified: 11 Apr 2025

    The Play method in the UUPlayer ActiveX control 6.0.0.1 in UUSee 2010 6.11.0609.2 allows remote attackers to execute arbitrary programs via a UNC share pathname in the MPlayerPath parameter.

    Published: 9 Aug 2011
    4.3
    Medium

    CVE-2011-2224

    Last Modified: 11 Apr 2025

    The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

    Published: 9 Aug 2011
    9.3
    Critical

    CVE-2011-2589

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the SendLogAction method in the UUPlayer ActiveX control 6.0.0.1 in UUSee 2010 6.11.0609.2 might allow remote attackers to execute arbitrary code via a long argument.

    Published: 9 Aug 2011
    5
    Medium

    CVE-2011-3013

    Last Modified: 11 Apr 2025

    WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 9 Aug 2011
    5
    Medium

    CVE-2011-3014

    Last Modified: 11 Apr 2025

    The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not properly restrict caching of HTTPS responses, which makes it easier for remote attackers to obtain sensitive information by leveraging an unattended workstation.

    Published: 9 Aug 2011
    10
    Critical

    CVE-2011-3012

    Last Modified: 11 Apr 2025

    The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file, a different vulnerability than CVE-2011-2764.

    Published: 9 Aug 2011
    5.8
    Medium

    CVE-2008-7294

    Last Modified: 11 Apr 2025

    Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

    Published: 9 Aug 2011
    5.8
    Medium

    CVE-2008-7296

    Last Modified: 11 Apr 2025

    Apple Safari cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

    Published: 9 Aug 2011
    4.3
    Medium

    CVE-2011-2379

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Bugzilla 2.4 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3, when Internet Explorer before 9 or Safari before 5.0.6 is used for Raw Unified mode, allows remote attackers to inject arbitrary web script or HTML via a crafted patch, related to content sniffing.

    Published: 9 Aug 2011