CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2011-0248

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the QuickTime ActiveX control in Apple QuickTime before 7.7 on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTL file.

    Published: 4 Aug 2011
    5.1
    Medium

    CVE-2011-3170

    Last Modified: 11 Apr 2025

    The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.

    Published: 4 Aug 2011
    2.1
    Low

    CVE-2013-0241

    Last Modified: 11 Apr 2025

    The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemu_mutex mutex. NOTE: some of these details are obtained from third party information.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2358

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 does not ensure that extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2359

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 3 Aug 2011
    4.3
    Medium

    CVE-2011-2360

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 does not ensure that the user is prompted before download of a dangerous file, which makes it easier for remote attackers to bypass intended content restrictions via a crafted web site.

    Published: 3 Aug 2011
    4.3
    Medium

    CVE-2011-2361

    Last Modified: 11 Apr 2025

    The Basic Authentication dialog implementation in Google Chrome before 13.0.782.107 does not properly handle strings, which might make it easier for remote attackers to capture credentials via a crafted web site.

    Published: 3 Aug 2011
    3.5
    Low

    CVE-2011-2711

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the print_fileinfo function in ui-diff.c in cgit 0.9.0.2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the filename associated with the rename hint.

    Published: 3 Aug 2011
    4.3
    Medium

    CVE-2011-2782

    Last Modified: 11 Apr 2025

    The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2783

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 does not ensure that developer-mode NPAPI extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.

    Published: 3 Aug 2011
    2.1
    Low

    CVE-2011-2784

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 allows remote attackers to obtain sensitive information via a request for the GL program log, which reveals a local path in an unspecified log entry.

    Published: 3 Aug 2011
    4.3
    Medium

    CVE-2011-2787

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 does not properly address re-entrancy issues associated with the GPU lock, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2788

    Last Modified: 11 Apr 2025

    Buffer overflow in the inspector serialization functionality in Google Chrome before 13.0.782.107 allows user-assisted remote attackers to have an unspecified impact via unknown vectors.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2789

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to instantiation of the Pepper plug-in.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2790

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving floating styles.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2791

    Last Modified: 11 Apr 2025

    The International Components for Unicode (ICU) functionality in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2792

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float removal.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2797

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to resource caching.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2798

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 does not properly restrict access to internal schemes, which allows remote attackers to have an unspecified impact via a crafted web site.

    Published: 3 Aug 2011
    4.3
    Medium

    CVE-2011-2800

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 allows remote attackers to obtain potentially sensitive information about client-side redirect targets via a crafted web site.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2801

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the frame loader.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2802

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 13.0.782.107, does not properly perform const lookups, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted web site.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2803

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 does not properly handle Skia paths, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 3 Aug 2011
    4.3
    Medium

    CVE-2011-2804

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 does not properly handle nested functions in PDF documents, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted document.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2805

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and conduct script injection attacks via unspecified vectors.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2818

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to display box rendering.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2819

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vectors related to handling of the base URI.

    Published: 3 Aug 2011
    4.3
    Medium

    CVE-2011-2786

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 does not ensure that the speech-input bubble is shown on the product's screen, which might make it easier for remote attackers to make audio recordings via a crafted web page containing an INPUT element.

    Published: 3 Aug 2011
    4.3
    Medium

    CVE-2011-2795

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 does not prevent calls to functions in other frames, which allows remote attackers to bypass intended access restrictions via a crafted web site, related to a "cross-frame function leak."

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2796

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Skia, as used in Google Chrome before 13.0.782.107, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 3 Aug 2011
    4.3
    Medium

    CVE-2011-2785

    Last Modified: 11 Apr 2025

    The extensions implementation in Google Chrome before 13.0.782.107 does not properly validate the URL for the home page, which allows remote attackers to have an unspecified impact via a crafted extension.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2793

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media selectors.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2794

    Last Modified: 11 Apr 2025

    Google Chrome before 13.0.782.107 does not properly perform text iteration, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2799

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to HTML range handling.

    Published: 3 Aug 2011
    6.8
    Medium

    CVE-2011-2975

    Last Modified: 11 Apr 2025

    Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data.

    Published: 1 Aug 2011
    2.1
    Low

    CVE-2011-1742

    Last Modified: 11 Apr 2025

    EMC Data Protection Advisor before 5.8.1 places cleartext account credentials in the DPA configuration file in unspecified circumstances, which might allow local users to obtain sensitive information by reading this file.

    Published: 1 Aug 2011
    7.8
    High

    CVE-2011-2399

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Media Management Daemon (mmd) in HP Data Protector 6.11 and earlier allows remote attackers to cause a denial of service via unknown vectors.

    Published: 1 Aug 2011
    4.3
    Medium

    CVE-2011-2402

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Aug 2011
    6.5
    Medium

    CVE-2011-2403

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 1 Aug 2011
    2.6
    Low

    CVE-2011-2642

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name.

    Published: 1 Aug 2011
    7.5
    High

    CVE-2011-2703

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.

    Published: 1 Aug 2011
    7.5
    High

    CVE-2011-2704

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter encoding.

    Published: 1 Aug 2011
    6
    Medium

    CVE-2011-2718

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the relational schema implementation in phpMyAdmin 3.4.x before 3.4.3.2 allow remote authenticated users to include and execute arbitrary local files via directory traversal sequences in an export type field, related to (1) libraries/schema/User_Schema.class.php and (2) schema_export.php.

    Published: 1 Aug 2011
    6.4
    Medium

    CVE-2011-2719

    Last Modified: 11 Apr 2025

    libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SESSION superglobal array, other superglobal arrays, and certain swekey.auth.lib.php local variables via a crafted query string, a related issue to CVE-2011-2505.

    Published: 1 Aug 2011
    5.8
    Medium

    CVE-2011-1744

    Last Modified: 11 Apr 2025

    EMC Captiva eInput 2.1.1 before 2.1.1.37 does not restrict the origin of calls to ActiveX functions, which allows remote attackers to read arbitrary files or cause a denial of service via a crafted web site.

    Published: 1 Aug 2011
    4.3
    Medium

    CVE-2011-1743

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in EMC Captiva eInput 2.1.1 before 2.1.1.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Aug 2011
    6.8
    Medium

    CVE-2011-2643

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.

    Published: 1 Aug 2011
    3.5
    Low

    CVE-2011-5000

    Last Modified: 11 Apr 2025

    The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant.

    Published: 1 Aug 2011
    5.1
    Medium

    CVE-2011-2899

    Last Modified: 11 Apr 2025

    pysmb.py in system-config-printer 0.6.x and 0.7.x, as used in foomatic-gui and possibly other products, allows remote SMB servers to execute arbitrary commands via shell metacharacters in the (1) NetBIOS or (2) workgroup name, which are not properly handled when searching for network printers.

    Published: 30 Jul 2011
    4.6
    Medium

    CVE-2011-4578

    Last Modified: 11 Apr 2025

    event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within directories created by a script, or (2) read files created by a script, via standard filesystem system calls.

    Published: 30 Jul 2011