CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-4810

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote attackers to execute arbitrary PHP code via a URL in the theme_file parameter to (1) includes/window_top.php and (2) header.php, and the (3) lang_file parameter to control/common.php.

    Published: 8 Jul 2011
    4.3
    Medium

    CVE-2010-4811

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ajaxmember.php in 6kbbs 8.0 build 20100901 allow remote attackers to inject arbitrary web script or HTML via the (1) user[msn], (2) user[email], and (3) user[phone] parameters in a modifyDetails action.

    Published: 8 Jul 2011
    7.5
    High

    CVE-2010-4808

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Webmatic allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Published: 8 Jul 2011
    3.5
    Low

    CVE-2010-4813

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Category Tokens module 6.x before 6.x-1.1 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML by editing or creating vocabulary names, which are not properly handled in token help.

    Published: 8 Jul 2011
    3.6
    Low

    CVE-2011-2664

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Check Point Multi-Domain Management / Provider-1 NGX R65, R70, R71, and R75, and SmartCenter during installation on non-Windows machines, allows local users on the MDS system to overwrite arbitrary files via unknown vectors.

    Published: 8 Jul 2011
    10
    Critical

    CVE-2011-2344

    Last Modified: 11 Apr 2025

    Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain privileges and access private pictures and web albums by sniffing the token from connections with picasaweb.google.com.

    Published: 8 Jul 2011
    4.3
    Medium

    CVE-2011-1001

    Last Modified: 11 Apr 2025

    dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malformed APK or dex file that calls a method using more arguments than the number of register that have been declared for that method.

    Published: 8 Jul 2011
    9.3
    Critical

    CVE-2011-0226

    Last Modified: 11 Apr 2025

    Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Type 1 font in a PDF document, as exploited in the wild in July 2011.

    Published: 8 Jul 2011
    6
    Medium

    CVE-2011-2707

    Last Modified: 11 Apr 2025

    The ptrace_setxregs function in arch/xtensa/kernel/ptrace.c in the Linux kernel before 3.1 does not validate user-space pointers, which allows local users to obtain sensitive information from kernel memory locations via a crafted PTRACE_SETXTREGS request.

    Published: 8 Jul 2011
    6.4
    Medium

    CVE-2011-4939

    Last Modified: 11 Apr 2025

    The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.

    Published: 8 Jul 2011
    4.3
    Medium

    CVE-2011-1224

    Last Modified: 11 Apr 2025

    IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue manager, or (3) application.

    Published: 7 Jul 2011
    4.3
    Medium

    CVE-2011-1498

    Last Modified: 11 Apr 2025

    Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.

    Published: 7 Jul 2011
    7.2
    High

    CVE-2011-1946

    Last Modified: 11 Apr 2025

    gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid function, which allows local users to gain privileges by leveraging access to two unprivileged user accounts, and running many processes under one of these accounts.

    Published: 7 Jul 2011
    6.8
    Medium

    CVE-2011-1931

    Last Modified: 11 Apr 2025

    sp5xdec.c in the Sunplus SP5X JPEG decoder in libavcodec in FFmpeg before 0.6.3 and libav through 0.6.2, as used in VideoLAN VLC media player 1.1.9 and earlier and other products, performs a write operation outside the bounds of an unspecified array, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a malformed AMV file.

    Published: 7 Jul 2011
    9.3
    Critical

    CVE-2011-1336

    Last Modified: 11 Apr 2025

    Buffer overflow in ALZip 8.21 and earlier allows remote attackers to execute arbitrary code via a crafted mim file.

    Published: 7 Jul 2011
    6.8
    Medium

    CVE-2011-2678

    Last Modified: 11 Apr 2025

    The Cisco VPN Client 5.0.7.0240 and 5.0.7.0290 on 64-bit Windows platforms uses weak permissions (NT AUTHORITY\INTERACTIVE:F) for cvpnd.exe, which allows local users to gain privileges by replacing this executable file with an arbitrary program, aka Bug ID CSCtn50645. NOTE: this vulnerability exists because of a CVE-2007-4415 regression.

    Published: 7 Jul 2011
    10
    Critical

    CVE-2011-2680

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 has unknown impact and remote attack vectors related to the "server error response."

    Published: 7 Jul 2011
    10
    Critical

    CVE-2011-2681

    Last Modified: 11 Apr 2025

    IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 does not properly handle exceptions, which has unspecified impact and remote attack vectors.

    Published: 7 Jul 2011
    4
    Medium

    CVE-2011-2682

    Last Modified: 11 Apr 2025

    The Login component in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 allows remote authenticated users to cause a denial of service (license consumption) by trying to login to DOORS Web Access with a new user account that has never been used for a DOORS login.

    Published: 7 Jul 2011
    4.3
    Medium

    CVE-2011-2679

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Jul 2011
    4.6
    Medium

    CVE-2011-1936

    Last Modified: 11 Apr 2025

    Xen, when using x86 Intel processors and the VMX virtualization extension is enabled, does not properly handle cpuid instruction emulation when exiting the VM, which allows local guest users to cause a denial of service (guest crash) via unspecified vectors.

    Published: 7 Jul 2011
    8.8
    High

    CVE-2011-2692

    Last Modified: 11 Apr 2025

    The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted PNG image that triggers the reading of uninitialized memory.

    Published: 7 Jul 2011
    6.1
    Medium

    CVE-2011-1780

    Last Modified: 11 Apr 2025

    The instruction emulation in Xen 3.0.3 allows local SMP guest users to cause a denial of service (host crash) by replacing the instruction that causes the VM to exit in one thread with a different instruction in a different thread.

    Published: 7 Jul 2011
    8.8
    High

    CVE-2011-2690

    Last Modified: 11 Apr 2025

    Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, allows remote attackers to overwrite memory with an arbitrary amount of data, and possibly have unspecified other impact, via a crafted PNG image.

    Published: 7 Jul 2011
    6.5
    Medium

    CVE-2011-2691

    Last Modified: 11 Apr 2025

    The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote attackers to cause a denial of service (application crash) via a crafted PNG image.

    Published: 7 Jul 2011
    5
    Medium

    CVE-2011-2529

    Last Modified: 11 Apr 2025

    chan_sip.c in the SIP channel driver in Asterisk Open Source 1.6.x before 1.6.2.18.1 and 1.8.x before 1.8.4.3 does not properly handle '\0' characters in SIP packets, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted packet.

    Published: 6 Jul 2011
    5
    Medium

    CVE-2011-2536

    Last Modified: 11 Apr 2025

    chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1.6.2.18.2, and 1.8.x before 1.8.4.4, and Asterisk Business Edition C.3.x before C.3.7.3, disregards the alwaysauthreject option and generates different responses for invalid SIP requests depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of requests.

    Published: 6 Jul 2011
    5
    Medium

    CVE-2011-2665

    Last Modified: 11 Apr 2025

    reqresp_parser.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.4.3 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a SIP packet with a Contact header that lacks a < (less than) character.

    Published: 6 Jul 2011
    5
    Medium

    CVE-2011-2666

    Last Modified: 11 Apr 2025

    The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, which allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames, a different vulnerability than CVE-2011-2536.

    Published: 6 Jul 2011
    5
    Medium

    CVE-2011-2535

    Last Modified: 11 Apr 2025

    chan_iax2.c in the IAX2 channel driver in Asterisk Open Source 1.4.x before 1.4.41.1, 1.6.2.x before 1.6.2.18.1, and 1.8.x before 1.8.4.3, and Asterisk Business Edition C.3 before C.3.7.3, accesses a memory address contained in an option control frame, which allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted frame.

    Published: 6 Jul 2011
    5
    Medium

    CVE-2011-2464

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.

    Published: 5 Jul 2011
    2.6
    Low

    CVE-2011-2465

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or certain CNAME records, allows remote attackers to cause a denial of service (named daemon crash) via an unspecified query.

    Published: 5 Jul 2011
    7.4
    High

    CVE-2011-2212

    Last Modified: 11 Apr 2025

    Buffer overflow in the virtio subsystem in qemu-kvm 0.14.0 and earlier allows privileged guest users to cause a denial of service (guest crash) or gain privileges via a crafted indirect descriptor related to "virtqueue in and out requests."

    Published: 5 Jul 2011
    6.5
    Medium

    CVE-2011-1526

    Last Modified: 11 Apr 2025

    ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script.

    Published: 5 Jul 2011
    9.8
    Critical

    CVE-2011-2523

    Last Modified: 21 Nov 2024

    vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

    Published: 4 Jul 2011
    5
    Medium

    CVE-2011-2705

    Last Modified: 11 Apr 2025

    The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.

    Published: 2 Jul 2011
    5
    Medium

    CVE-2011-2686

    Last Modified: 11 Apr 2025

    Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to CVE-2003-0900. NOTE: this issue exists because of a regression during Ruby 1.8.6 development.

    Published: 2 Jul 2011
    5
    Medium

    CVE-2011-3009

    Last Modified: 11 Apr 2025

    Ruby before 1.8.6-p114 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to CVE-2003-0900.

    Published: 2 Jul 2011
    10
    Critical

    CVE-2011-1866

    Last Modified: 11 Apr 2025

    Buffer overflow in omniinet.exe in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to execute arbitrary code via a crafted request, related to the EXEC_CMD functionality.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2615

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.50 allows remote attackers to cause a denial of service (application hang) via unknown content on a web page, as demonstrated by domiteca.com.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2616

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.50 allows remote attackers to cause a denial of service (memory consumption) via unknown content on a web page, as demonstrated by test262.ecmascript.org.

    Published: 1 Jul 2011
    4.3
    Medium

    CVE-2011-1337

    Last Modified: 11 Apr 2025

    Opera before 11.50 allows remote attackers to cause a denial of service (disk consumption) via invalid URLs that trigger creation of error pages.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-1514

    Last Modified: 11 Apr 2025

    The inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request containing crafted parameters.

    Published: 1 Jul 2011
    6.4
    Medium

    CVE-2011-2608

    Last Modified: 11 Apr 2025

    ovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60.008, 8.60.501, and 8.53; allows remote attackers to delete arbitrary files via a full pathname in the File field in a Register command.

    Published: 1 Jul 2011
    4.3
    Medium

    CVE-2011-2609

    Last Modified: 11 Apr 2025

    Opera before 11.50 does not properly restrict data: URIs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.

    Published: 1 Jul 2011
    10
    Critical

    CVE-2011-2610

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.50 has unknown impact and attack vectors, related to a "moderately severe issue."

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2618

    Last Modified: 11 Apr 2025

    Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via web script that moves a (1) AUDIO element or (2) VIDEO element between windows.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2619

    Last Modified: 11 Apr 2025

    Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via a gradient with many stops, related to the implementation of CANVAS elements, SVG, and Cascading Style Sheets (CSS).

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2620

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via vectors involving SVG animation.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2621

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via vectors related to form layout.

    Published: 1 Jul 2011