CVE Feed

    Dashboard / CVE

    2.6
    Low

    CVE-2011-2694

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username parameter to the passwd program (aka the user field to the Change Password page).

    Published: 26 Jul 2011
    3.7
    Low

    CVE-2011-2503

    Last Modified: 11 Apr 2025

    The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local users to gain privileges via a race condition between the signature validation and the module initialization.

    Published: 25 Jul 2011
    6.8
    Medium

    CVE-2011-2725

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.

    Published: 25 Jul 2011
    4.4
    Medium

    CVE-2011-2502

    Last Modified: 11 Apr 2025

    runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.

    Published: 25 Jul 2011
    5.5
    Medium

    CVE-2011-2918

    Last Modified: 11 Apr 2025

    The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with PERF_COUNT_SW_CPU_CLOCK events, which allows local users to cause a denial of service (system hang) via a crafted application.

    Published: 22 Jul 2011
    5
    Medium

    CVE-2011-0214

    Last Modified: 11 Apr 2025

    CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote web servers to bypass intended SSL restrictions via a certificate signed by a blacklisted certification authority.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0215

    Last Modified: 11 Apr 2025

    ImageIO in Apple Safari before 5.0.6 on Windows does not properly address re-entrancy issues, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file.

    Published: 21 Jul 2011
    5.8
    Medium

    CVE-2011-0219

    Last Modified: 11 Apr 2025

    Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites, via a Java applet that loads fonts.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0223

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0234

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0235

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0241

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in ImageIO in Apple Safari before 5.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with CCITT Group 4 encoding.

    Published: 21 Jul 2011
    4.3
    Medium

    CVE-2011-0242

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving a URL that contains a username.

    Published: 21 Jul 2011
    4.3
    Medium

    CVE-2011-0244

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files via vectors related to improper canonicalization of URLs within RSS feeds.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-1288

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-1457

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-1462

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    8.8
    High

    CVE-2011-1774

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted web site. NOTE: this may overlap CVE-2011-1425.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-2883

    Last Modified: 11 Apr 2025

    The NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 attempts to validate signed DLLs by checking the certificate subject, not the signature, which allows man-in-the-middle attackers to execute arbitrary code via HTTP header data referencing a DLL that was signed with a crafted certificate.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2010-1383

    Last Modified: 11 Apr 2025

    CFNetwork in Apple Safari before 5.0.6 on Windows allows remote web servers to execute arbitrary code by replaying the NTLM credentials of a client user, related to a "credential reflection" issue.

    Published: 21 Jul 2011
    4.3
    Medium

    CVE-2010-1420

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in CFNetwork in Apple Safari before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted text/plain file.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0218

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0222

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0225

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0232

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0233

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0238

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0253

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0255

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-1453

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-1797

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-2882

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 allows remote attackers to execute arbitrary code via crafted HTTP header data.

    Published: 21 Jul 2011
    4.3
    Medium

    CVE-2011-0217

    Last Modified: 11 Apr 2025

    Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fields.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0221

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0237

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0240

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    9.3
    Critical

    CVE-2011-0254

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Published: 21 Jul 2011
    4.4
    Medium

    CVE-2011-2264

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.2.0 and 8.3.5.0 allows context-dependent attackers to affect confidentiality, integrity, and availability via unknown vectors related to Outside In Filters. NOTE: the previous information was obtained from the July 2011 CPU. Oracle has not commented on claims from a reliable third party that this is a stack-based buffer overflow in the imcdr2.flt library for the CorelDRAW parser.

    Published: 21 Jul 2011
    5.5
    Medium

    CVE-2011-2272

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise FSCM component in Oracle PeopleSoft Products 9.0, Bundle, #36, 9.1, Bundle, and #13 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to eProcurement.

    Published: 21 Jul 2011
    4
    Medium

    CVE-2011-2273

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Agile Core Technology component in Oracle Supply Chain Products Suite 9.3.0.3 and 9.3.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Search.

    Published: 21 Jul 2011
    5.5
    Medium

    CVE-2011-2279

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1, Bundle, and #6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Manager.

    Published: 21 Jul 2011
    5.5
    Medium

    CVE-2011-2281

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 8.9 Update 2011-D allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Global Payroll Core.

    Published: 21 Jul 2011
    3.5
    Low

    CVE-2011-2282

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50.20 and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors.

    Published: 21 Jul 2011
    5.5
    Medium

    CVE-2011-2283

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise FMS component in Oracle PeopleSoft Products 9.0 Bundle #36 and 9.1 Bundle #13 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Payables.

    Published: 21 Jul 2011
    7.8
    High

    CVE-2011-2287

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to fingerd.

    Published: 21 Jul 2011
    4.9
    Medium

    CVE-2011-2290

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel/sockfs.

    Published: 21 Jul 2011
    1.7
    Low

    CVE-2011-2291

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality via unknown vectors related to Trusted Extensions.

    Published: 21 Jul 2011
    4.9
    Medium

    CVE-2011-2293

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability via unknown vectors related to Zones.

    Published: 21 Jul 2011
    4.7
    Medium

    CVE-2011-2295

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability, related to Driver/USB.

    Published: 21 Jul 2011
    4.9
    Medium

    CVE-2011-2296

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability, related to Kernel/SCTP.

    Published: 21 Jul 2011