CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2011-1127

    Last Modified: 11 Apr 2025

    SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote attackers to have an unspecified impact via unknown vectors.

    Published: 21 Jun 2011
    7.5
    High

    CVE-2011-1128

    Last Modified: 11 Apr 2025

    The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle invalid login attempts, which might make it easier for remote attackers to obtain access or cause a denial of service via a brute-force attack.

    Published: 21 Jun 2011
    3.5
    Low

    CVE-2011-1129

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the EditNews function in ManageNews.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, might allow remote authenticated users to inject arbitrary web script or HTML via a save_items action.

    Published: 21 Jun 2011
    7.5
    High

    CVE-2011-1130

    Last Modified: 11 Apr 2025

    Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote attackers to conduct SQL injection attacks, obtain sensitive information, or cause a denial of service via a crafted value, related to the cleanRequest function in QueryString.php and the constructPageIndex function in Subs.php.

    Published: 21 Jun 2011
    7.5
    High

    CVE-2011-1480

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands via the chng_uid parameter.

    Published: 21 Jun 2011
    6.8
    Medium

    CVE-2011-1482

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in mainfile.php in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts or (2) grant the administrative privilege to a user account, related to a Referer check that uses a substring comparison.

    Published: 21 Jun 2011
    5
    Medium

    CVE-2011-1753

    Last Modified: 11 Apr 2025

    expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Published: 21 Jun 2011
    5
    Medium

    CVE-2011-1754

    Last Modified: 11 Apr 2025

    jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Published: 21 Jun 2011
    5
    Medium

    CVE-2011-1756

    Last Modified: 11 Apr 2025

    modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Published: 21 Jun 2011
    5
    Medium

    CVE-2011-2188

    Last Modified: 11 Apr 2025

    LuaExpat before 1.2.0 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Published: 21 Jun 2011
    4.3
    Medium

    CVE-2011-1481

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sender_name or (2) sender_email parameter in a Feedback action to modules.php.

    Published: 21 Jun 2011
    5
    Medium

    CVE-2011-1131

    Last Modified: 11 Apr 2025

    The PlushSearch2 function in Search.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, uses certain cached data in a situation where a temporary table has been created, even though this cached data is intended only for situations where a temporary table has not been created, which might allow remote attackers to obtain sensitive information via a search.

    Published: 21 Jun 2011
    5
    Medium

    CVE-2011-1757

    Last Modified: 11 Apr 2025

    DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Published: 21 Jun 2011
    10
    Critical

    CVE-2011-0085

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater.

    Published: 21 Jun 2011
    10
    Critical

    CVE-2011-2364

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbird before 3.1.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2365.

    Published: 21 Jun 2011
    10
    Critical

    CVE-2011-2365

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbird before 3.1.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2364.

    Published: 21 Jun 2011
    10
    Critical

    CVE-2011-2374

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 21 Jun 2011
    2.1
    Low

    CVE-2011-2494

    Last Modified: 11 Apr 2025

    kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.

    Published: 21 Jun 2011
    10
    Critical

    CVE-2011-2363

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.

    Published: 21 Jun 2011
    10
    Critical

    CVE-2011-2376

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.18 and Thunderbird before 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 21 Jun 2011
    2.1
    Low

    CVE-2011-2495

    Last Modified: 11 Apr 2025

    fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly restrict access to /proc/#####/io files, which allows local users to obtain sensitive I/O statistics by polling a file, as demonstrated by discovering the length of another user's password.

    Published: 21 Jun 2011
    4.3
    Medium

    CVE-2011-2605

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.

    Published: 21 Jun 2011
    10
    Critical

    CVE-2011-0083

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.

    Published: 21 Jun 2011
    5
    Medium

    CVE-2011-2362

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 do not distinguish between cookies for two domain names that differ only in a trailing dot, which allows remote web servers to bypass the Same Origin Policy via Set-Cookie headers.

    Published: 21 Jun 2011
    10
    Critical

    CVE-2011-2371

    Last Modified: 11 Apr 2025

    Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object.

    Published: 21 Jun 2011
    7.6
    High

    CVE-2011-2373

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14, when JavaScript is disabled, allows remote attackers to execute arbitrary code via a crafted XUL document.

    Published: 21 Jun 2011
    10
    Critical

    CVE-2011-2375

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 5.0 and Thunderbird through 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 21 Jun 2011
    5
    Medium

    CVE-2011-2483

    Last Modified: 11 Apr 2025

    crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.

    Published: 20 Jun 2011
    6.5
    Medium

    CVE-2011-1594

    Last Modified: 2 Apr 2026

    A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks, potentially leading to unauthorized information disclosure or credential theft.

    Published: 20 Jun 2011
    4.3
    Medium

    CVE-2011-2698

    Last Modified: 11 Apr 2025

    Off-by-one error in the elem_cell_id_aux function in epan/dissectors/packet-ansi_a.c in the ANSI MAP dissector in Wireshark 1.4.x before 1.4.8 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (infinite loop) via an invalid packet.

    Published: 20 Jun 2011
    5
    Medium

    CVE-2012-5621

    Last Modified: 12 Apr 2025

    lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection with a party name that contains invalid UTF-8 strings.

    Published: 20 Jun 2011
    9.3
    Critical

    CVE-2011-2109

    Last Modified: 11 Apr 2025

    Multiple integer overflows in Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allow attackers to execute arbitrary code via unspecified vectors.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-0318

    Last Modified: 11 Apr 2025

    Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0317, CVE-2011-0319, CVE-2011-0320, CVE-2011-0335, CVE-2011-2119, and CVE-2011-2122.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-0319

    Last Modified: 11 Apr 2025

    Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0317, CVE-2011-0318, CVE-2011-0320, CVE-2011-0335, CVE-2011-2119, and CVE-2011-2122.

    Published: 16 Jun 2011
    5
    Medium

    CVE-2011-2091

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to cause a denial of service via unknown vectors.

    Published: 16 Jun 2011
    10
    Critical

    CVE-2011-2092

    Last Modified: 11 Apr 2025

    Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a "deserialization vulnerability."

    Published: 16 Jun 2011
    6.9
    Medium

    CVE-2011-2100

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2106

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2111

    Last Modified: 11 Apr 2025

    IML32.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2115 and CVE-2011-2116.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2112

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in IML32.dll in Adobe Shockwave Player before 11.6.0.626 allow attackers to execute arbitrary code via unspecified vectors.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2116

    Last Modified: 11 Apr 2025

    IML32.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2111 and CVE-2011-2115.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2117

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2114, CVE-2011-2124, CVE-2011-2127, and CVE-2011-2128.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2118

    Last Modified: 11 Apr 2025

    The FLV ASSET Xtra component in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors, related to an "input validation vulnerability."

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2120

    Last Modified: 11 Apr 2025

    Integer overflow in the CursorAsset x32 component in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2121

    Last Modified: 11 Apr 2025

    Integer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2123

    Last Modified: 11 Apr 2025

    Integer overflow in the Shockwave 3D Asset x32 component in Adobe Shockwave Player before 11.6.0.626 allows remote attackers to execute arbitrary code via a crafted subrecord in a DEMX chunk, which triggers a heap-based buffer overflow.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2124

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2114, CVE-2011-2117, CVE-2011-2127, and CVE-2011-2128.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2125

    Last Modified: 11 Apr 2025

    Buffer overflow in Dirapix.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2126

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 16 Jun 2011
    9.3
    Critical

    CVE-2011-2127

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2114, CVE-2011-2117, CVE-2011-2124, and CVE-2011-2128.

    Published: 16 Jun 2011