CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2011-2622

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Web Workers implementation in Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via unknown vectors.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2623

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the SVG BiDi implementation in Opera before 11.50 allows remote attackers to cause a denial of service (application crash or hang) via unknown vectors.

    Published: 1 Jul 2011
    4.3
    Medium

    CVE-2011-2624

    Last Modified: 11 Apr 2025

    Opera before 11.50 allows user-assisted remote attackers to cause a denial of service (application hang) via a large table, which is not properly handled during a print preview.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2626

    Last Modified: 11 Apr 2025

    Opera before 11.50 allows remote attackers to cause a denial of service (application crash) by using "injected script" to set the SRC attribute of an IFRAME element.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2627

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the DOM implementation in Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via unknown content on a web page, as demonstrated by live.com.

    Published: 1 Jul 2011
    10
    Critical

    CVE-2011-2628

    Last Modified: 11 Apr 2025

    Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to page unload.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2629

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.11 allows remote attackers to cause a denial of service (application crash) via unknown content on a web page, as demonstrated by www.falk.de.

    Published: 1 Jul 2011
    4.3
    Medium

    CVE-2011-2630

    Last Modified: 11 Apr 2025

    Opera before 11.11 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web page that is not properly handled during a reload occurring after the opening of a popup of the Easy Sticky Note extension.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2631

    Last Modified: 11 Apr 2025

    The Cascading Style Sheets (CSS) implementation in Opera before 11.11 does not properly handle the column-count property, which allows remote attackers to cause a denial of service (infinite repaint loop and application hang) via a web page, as demonstrated by an unspecified Wikipedia page.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2632

    Last Modified: 11 Apr 2025

    Opera before 11.11 does not properly handle destruction of a Silverlight instance, which allows remote attackers to cause a denial of service (application crash) via a web page, as demonstrated by vod.onet.pl.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2633

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.11 allows remote attackers to cause a denial of service (application crash) via vectors involving a Certificate Revocation List (CRL) file, as demonstrated by the multicert-ca-02.crl file.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2635

    Last Modified: 11 Apr 2025

    The Cascading Style Sheets (CSS) implementation in Opera before 11.10 allows remote attackers to cause a denial of service (application crash) via vectors involving use of the :hover pseudo-class, in conjunction with transforms, for a floated element.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2636

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.10 allows remote attackers to cause a denial of service (application crash) via unknown content on a web page, as demonstrated by a certain Tomato Firmware page.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2637

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.10 allows remote attackers to cause a denial of service (application crash) via unknown content on a web page, as demonstrated by futura-sciences.com, seoptimise.com, and mitosyfraudes.org.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2638

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.10 allows remote attackers to cause a denial of service (application crash) via unknown content on a web page, as demonstrated by games on zylom.com.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2639

    Last Modified: 11 Apr 2025

    Opera before 11.10 does not properly handle hidden animated GIF images, which allows remote attackers to cause a denial of service (CPU consumption) via an image file that triggers continual repaints.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2640

    Last Modified: 11 Apr 2025

    Opera before 11.10 allows remote attackers to cause a denial of service (application crash) via an HTML document that has an empty parameter value for an embedded Java applet.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2641

    Last Modified: 11 Apr 2025

    Opera 11.11 allows remote attackers to cause a denial of service (application crash) by setting the FACE attribute of a FONT element within an IFRAME element after changing the SRC attribute of this IFRAME element to an about:blank value.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2614

    Last Modified: 11 Apr 2025

    The SVG implementation in Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via vectors involving a path on which many characters are drawn.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2617

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via vectors related to selecting a text node, and closed pop-up windows, removed pop-up windows, and IFRAME elements.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-1515

    Last Modified: 11 Apr 2025

    The inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to cause a denial of service (daemon exit) via a request containing crafted parameters.

    Published: 1 Jul 2011
    10
    Critical

    CVE-2011-1865

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to execute arbitrary code via a request containing crafted parameters.

    Published: 1 Jul 2011
    4.3
    Medium

    CVE-2011-2611

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the printing functionality in Opera before 11.50 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web page.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2612

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via unknown content on a web page, as demonstrated by progorod.ru.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2613

    Last Modified: 11 Apr 2025

    The Array.prototype.join method in Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via a non-array object that contains initial holes.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2625

    Last Modified: 11 Apr 2025

    Opera before 11.50 allows remote attackers to cause a denial of service (application crash) via a SELECT element that contains many OPTION elements.

    Published: 1 Jul 2011
    5
    Medium

    CVE-2011-2634

    Last Modified: 11 Apr 2025

    Opera before 11.10 allows remote attackers to hijack (1) searches and (2) customizations via unspecified third party applications.

    Published: 1 Jul 2011
    5.3
    Medium

    CVE-2011-2515

    Last Modified: 21 Nov 2024

    PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.

    Published: 1 Jul 2011
    6.4
    Medium

    CVE-2011-2367

    Last Modified: 11 Apr 2025

    The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sensitive information from GPU memory associated with an arbitrary process, or cause a denial of service (application crash), via unspecified vectors.

    Published: 30 Jun 2011
    5
    Medium

    CVE-2011-2370

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 5.0 does not properly enforce the whitelist for the xpinstall functionality, which allows remote attackers to trigger an installation dialog for a (1) add-on or (2) theme via unspecified vectors.

    Published: 30 Jun 2011
    4.3
    Medium

    CVE-2011-2606

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web UI in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165511.

    Published: 30 Jun 2011
    4.3
    Medium

    CVE-2011-2607

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 3.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Work Item 165513.

    Published: 30 Jun 2011
    4.3
    Medium

    CVE-2011-2369

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 4.0.1 allows remote attackers to inject arbitrary web script or HTML via an SVG element containing an HTML-encoded entity.

    Published: 30 Jun 2011
    10
    Critical

    CVE-2011-2368

    Last Modified: 11 Apr 2025

    The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict write operations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

    Published: 30 Jun 2011
    3.3
    Low

    CVE-2009-5082

    Last Modified: 11 Apr 2025

    The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file.

    Published: 30 Jun 2011
    7.1
    High

    CVE-2011-2600

    Last Modified: 11 Apr 2025

    The GPU support functionality in Windows XP does not properly restrict rendering time, which allows remote attackers to cause a denial of service (system crash) via vectors involving WebGL and (1) shader programs or (2) complex 3D geometry, as demonstrated by using Mozilla Firefox or Google Chrome to visit the lots-of-polys-example.html test page in the Khronos WebGL SDK.

    Published: 30 Jun 2011
    7.1
    High

    CVE-2011-2601

    Last Modified: 11 Apr 2025

    The GPU support functionality in Mac OS X does not properly restrict rendering time, which allows remote attackers to cause a denial of service (desktop hang) via vectors involving WebGL and (1) shader programs or (2) complex 3D geometry, as demonstrated by using Mozilla Firefox or Google Chrome to visit the lots-of-polys-example.html test page in the Khronos WebGL SDK.

    Published: 30 Jun 2011
    7.1
    High

    CVE-2011-2602

    Last Modified: 11 Apr 2025

    The NVIDIA Geforce 310 driver 6.14.12.7061 on Windows XP SP3 allows remote attackers to cause a denial of service (system crash) via a crafted web page that is visited with Google Chrome or Mozilla Firefox, as demonstrated by the lots-of-polys-example.html test page in the Khronos WebGL SDK.

    Published: 30 Jun 2011
    7.1
    High

    CVE-2011-2603

    Last Modified: 11 Apr 2025

    The NVIDIA 9400M driver 6.2.6 on Mac OS X 10.6.7 allows remote attackers to cause a denial of service (desktop hang) via a crafted web page that is visited with Google Chrome or Mozilla Firefox, as demonstrated by the lots-of-polys-example.html test page in the Khronos WebGL SDK.

    Published: 30 Jun 2011
    7.1
    High

    CVE-2011-2604

    Last Modified: 11 Apr 2025

    The Intel G41 driver 6.14.10.5355 on Windows XP SP3 allows remote attackers to cause a denial of service (system crash) via a crafted web page that is visited with Google Chrome or Mozilla Firefox, as demonstrated by the lots-of-polys-example.html test page in the Khronos WebGL SDK.

    Published: 30 Jun 2011
    3.3
    Low

    CVE-2009-5079

    Last Modified: 11 Apr 2025

    The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack on a gro#####.tmp or /tmp/##### temporary file.

    Published: 30 Jun 2011
    4.3
    Medium

    CVE-2011-2197

    Last Modified: 11 Apr 2025

    The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

    Published: 30 Jun 2011
    4.3
    Medium

    CVE-2011-2599

    Last Modified: 11 Apr 2025

    Google Chrome 11 does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.

    Published: 30 Jun 2011
    4.3
    Medium

    CVE-2011-2598

    Last Modified: 11 Apr 2025

    The WebGL implementation in Mozilla Firefox 4.x allows remote attackers to obtain screenshots of the windows of arbitrary desktop applications via vectors involving an SVG filter, an IFRAME element, and uninitialized data in graphics memory.

    Published: 30 Jun 2011
    4.3
    Medium

    CVE-2011-1332

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-6570.

    Published: 29 Jun 2011
    4.3
    Medium

    CVE-2011-1333

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Office 6 and Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to "downloading graphic files from the bulletin board system."

    Published: 29 Jun 2011
    4.3
    Medium

    CVE-2011-2180

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in dereferer.php in A Really Simple Chat (ARSC) 3.3-rc2 allows remote attackers to inject arbitrary web script or HTML via the arsc_link parameter.

    Published: 29 Jun 2011
    6.8
    Medium

    CVE-2011-2348

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 12.0.742.112, performs an incorrect bounds check, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 29 Jun 2011
    6.8
    Medium

    CVE-2011-2349

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to text selection.

    Published: 29 Jun 2011
    6.8
    Medium

    CVE-2011-2350

    Last Modified: 11 Apr 2025

    The HTML parser in Google Chrome before 12.0.742.112 does not properly address "lifetime and re-entrancy issues," which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 29 Jun 2011