CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2011-2230

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect availability via unknown vectors.

    Published: 20 Jul 2011
    4
    Medium

    CVE-2011-2238

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect integrity, related to DBMS_SYS_SQL.

    Published: 20 Jul 2011
    6.8
    Medium

    CVE-2011-0822

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Streams, AQ & Replication Mgmt component in Oracle Database Server 10.1.0.5 and 10.2.0.3, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 20 Jul 2011
    6.5
    Medium

    CVE-2011-0835

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2011-0832 and CVE-2011-0880.

    Published: 20 Jul 2011
    6.5
    Medium

    CVE-2011-0838

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to create procedure privileges.

    Published: 20 Jul 2011
    6.8
    Medium

    CVE-2011-0848

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Security Framework component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to User Model.

    Published: 20 Jul 2011
    4.3
    Medium

    CVE-2011-0879

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Instance Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5; allows remote attackers to affect integrity via unknown vectors.

    Published: 20 Jul 2011
    4.3
    Medium

    CVE-2011-2231

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the XML Developer Kit component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1, Oracle Fusion Middleware 10.1.3.5, allows remote attackers to affect availability via unknown vectors.

    Published: 20 Jul 2011
    6.8
    Medium

    CVE-2011-0882

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Content Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, and 11.1.0.7; and Oracle Enterprise Manager Grid Control 10.1.0.6, 10.2.0.5, and 11.1.0.1; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Scheduler.

    Published: 20 Jul 2011
    4
    Medium

    CVE-2011-0884

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle BPEL Process Manager component in Oracle Fusion Middleware 11.1.1.3.0, 11.1.1.4.0, and 11.1.1.5.0 allows remote authenticated users to affect availability, related to BPEL Console.

    Published: 20 Jul 2011
    6
    Medium

    CVE-2011-2232

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the XML Developer Kit component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 11.1.0.7, and 11.2.0.1, and Oracle Fusion Middleware 10.1.3.5, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 20 Jul 2011
    9.3
    Critical

    CVE-2011-0216

    Last Modified: 11 Apr 2025

    Off-by-one error in libxml in Apple Safari before 5.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted web site.

    Published: 20 Jul 2011
    5
    Medium

    CVE-2011-2513

    Last Modified: 12 Apr 2025

    The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader.

    Published: 20 Jul 2011
    7.5
    High

    CVE-2011-2699

    Last Modified: 11 Apr 2025

    The IPv6 implementation in the Linux kernel before 3.1 does not generate Fragment Identification values separately for each destination, which makes it easier for remote attackers to cause a denial of service (disrupted networking) by predicting these values and sending crafted packets.

    Published: 20 Jul 2011
    4.3
    Medium

    CVE-2011-2943

    Last Modified: 11 Apr 2025

    The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted nickname that is not properly handled in a WHO response.

    Published: 20 Jul 2011
    6.8
    Medium

    CVE-2011-2514

    Last Modified: 12 Apr 2025

    The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to represent a different filename than the file for which access will be granted.

    Published: 20 Jul 2011
    7.2
    High

    CVE-2011-0227

    Last Modified: 11 Apr 2025

    The queueing primitives in IOMobileFrameBuffer in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 do not properly perform type conversion, which allows local users to gain privileges via a crafted application.

    Published: 19 Jul 2011
    4.3
    Medium

    CVE-2011-2743

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the action parameter to (1) the default URI or (2) includes/javascript.php, or the (3) title or (4) body parameter to admin/help.php.

    Published: 19 Jul 2011
    5
    Medium

    CVE-2011-2780

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability than CVE-2011-2744.

    Published: 19 Jul 2011
    3.6
    Low

    CVE-2011-2779

    Last Modified: 11 Apr 2025

    Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 uses world-writable permissions for exported report files, which allows local users to change or delete log data by modifying a file, a different vulnerability than CVE-2011-0770.

    Published: 19 Jul 2011
    5.8
    Medium

    CVE-2011-1355

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage parameter.

    Published: 19 Jul 2011
    10
    Critical

    CVE-2011-1741

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in ftserver.exe in the OpenText Hummingbird Client Connector, as used in the Indexing Server in EMC Documentum eRoom 7.x before 7.4.3.f and other products, allows remote attackers to execute arbitrary code by sending a crafted message over TCP.

    Published: 19 Jul 2011
    6.5
    Medium

    CVE-2011-2385

    Last Modified: 11 Apr 2025

    The iPhoneHandle package 0.9.x before 0.9.7 and 1.0.x before 1.0.3 in Open Ticket Request System (OTRS) does not properly restrict use of the iPhoneHandle interface, which allows remote authenticated users to gain privileges, and consequently read or modify OTRS core objects, via unspecified vectors.

    Published: 19 Jul 2011
    6.8
    Medium

    CVE-2011-2744

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the action parameter to the default URI.

    Published: 19 Jul 2011
    4.3
    Medium

    CVE-2011-0770

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 allows remote attackers to inject arbitrary web script or HTML via the Windows XP variable in a file.

    Published: 19 Jul 2011
    2.1
    Low

    CVE-2011-1356

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows local users to obtain sensitive stack-trace information via a crafted Administration Console request.

    Published: 19 Jul 2011
    6.4
    Medium

    CVE-2011-1511

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 and 3.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to Administration.

    Published: 19 Jul 2011
    9.3
    Critical

    CVE-2011-3193

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.

    Published: 19 Jul 2011
    5.8
    Medium

    CVE-2011-2260

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Administration.

    Published: 19 Jul 2011
    9.3
    Critical

    CVE-2011-0548

    Last Modified: 11 Apr 2025

    Buffer overflow in the Lotus Freelance Graphics PRZ file viewer in Autonomy KeyView, as used in Symantec Mail Security (SMS) 6.x through 8.x, Symantec Brightmail and Messaging Gateway before 9.5.1, and Symantec Data Loss Prevention (DLP) before 10.5.3 and 11.x before 11.1, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .prz file. NOTE: this may overlap CVE-2011-1217.

    Published: 18 Jul 2011
    6.8
    Medium

    CVE-2010-3271

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that disable certain security options via an Edit action to console/adminSecurityDetail.do followed by a save action to console/syncworkspace.do.

    Published: 18 Jul 2011
    9.3
    Critical

    CVE-2011-1331

    Last Modified: 11 Apr 2025

    JustSystems Ichitaro 2005 through 2011, Ichitaro Government 6, Ichitaro Government 2006 through 2010, Ichitaro Portable, Ichitaro Pro, and Ichitaro Viewer allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted document, as exploited in the wild in early 2011.

    Published: 18 Jul 2011
    4.3
    Medium

    CVE-2011-2761

    Last Modified: 11 Apr 2025

    Google Chrome 14.0.794.0 does not properly handle a reload of a page generated in response to a POST, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web site, related to GetWidget methods.

    Published: 18 Jul 2011
    7.8
    High

    CVE-2011-2520

    Last Modified: 11 Apr 2025

    fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.

    Published: 18 Jul 2011
    6.8
    Medium

    CVE-2011-2196

    Last Modified: 11 Apr 2025

    jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enterprise Web Platform 5.1.1, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1484.

    Published: 18 Jul 2011
    7.2
    High

    CVE-2011-1223

    Last Modified: 11 Apr 2025

    Buffer overflow in the Alternate Data Stream (aka ADS or named stream) functionality in the backup-archive client in IBM Tivoli Storage Manager (TSM) before 5.4.3.4, 5.5.x before 5.5.3, 6.x before 6.1.4, and 6.2.x before 6.2.2 on Windows allows local users to gain privileges via unspecified vectors.

    Published: 17 Jul 2011
    5
    Medium

    CVE-2011-2750

    Last Modified: 11 Apr 2025

    NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.

    Published: 17 Jul 2011
    7.5
    High

    CVE-2011-2751

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Parodia before 6.809 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 Jul 2011
    5
    Medium

    CVE-2011-2755

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 17 Jul 2011
    5
    Medium

    CVE-2011-2757

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the FILENAME parameter. NOTE: this might overlap the US-CERT VU#543310 issue.

    Published: 17 Jul 2011
    5
    Medium

    CVE-2011-2758

    Last Modified: 11 Apr 2025

    IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for access to LDAP Server log files, which allows remote attackers to obtain sensitive information via a crafted URL.

    Published: 17 Jul 2011
    5
    Medium

    CVE-2011-2759

    Last Modified: 11 Apr 2025

    The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

    Published: 17 Jul 2011
    5
    Medium

    CVE-2011-2760

    Last Modified: 11 Apr 2025

    Brocade BigIron RX switches allow remote attackers to bypass ACL rules by using 179 as the source port of a packet.

    Published: 17 Jul 2011
    7.2
    High

    CVE-2011-1222

    Last Modified: 11 Apr 2025

    Buffer overflow in the Journal Based Backup (JBB) feature in the backup-archive client in IBM Tivoli Storage Manager (TSM) before 5.4.3.4, 5.5.x before 5.5.3, 6.x before 6.1.4, and 6.2.x before 6.2.2 on Windows and AIX allows local users to gain privileges via unspecified vectors.

    Published: 17 Jul 2011
    4.3
    Medium

    CVE-2011-2754

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as used in IBM Web Content Manager (WCM) and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Jul 2011
    5
    Medium

    CVE-2011-2756

    Last Modified: 11 Apr 2025

    FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors.

    Published: 17 Jul 2011
    4.6
    Medium

    CVE-2011-4099

    Last Modified: 11 Apr 2025

    The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restrictions via unspecified vectors.

    Published: 16 Jul 2011
    6.8
    Medium

    CVE-2011-2911

    Last Modified: 11 Apr 2025

    Integer overflow in the CSoundFile::ReadWav function in src/load_wav.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted WAV file, which triggers a heap-based buffer overflow.

    Published: 15 Jul 2011
    6.8
    Medium

    CVE-2011-2912

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the CSoundFile::ReadS3M function in src/load_s3m.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted S3M file with an invalid offset.

    Published: 15 Jul 2011
    6.8
    Medium

    CVE-2011-2913

    Last Modified: 11 Apr 2025

    Off-by-one error in the CSoundFile::ReadAMS function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service (stack memory corruption) and possibly execute arbitrary code via a crafted AMS file with a large number of samples.

    Published: 15 Jul 2011