CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2011-1858

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows local users to bypass intended access restrictions via unknown vectors.

    Published: 14 Jun 2011
    5
    Medium

    CVE-2011-1859

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 14 Jun 2011
    5
    Medium

    CVE-2011-1860

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to capture HTTP session credentials via unknown vectors.

    Published: 14 Jun 2011
    8.3
    High

    CVE-2011-1861

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to modify data or obtain sensitive information via unknown vectors.

    Published: 14 Jun 2011
    9.3
    Critical

    CVE-2011-1864

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 14 Jun 2011
    4.3
    Medium

    CVE-2011-2179

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action.

    Published: 14 Jun 2011
    4.3
    Medium

    CVE-2011-2476

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-4667.

    Published: 14 Jun 2011
    2.6
    Low

    CVE-2011-2477

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in Icinga before 1.4.1, when escape_html_tags is disabled, allow remote attackers to inject arbitrary web script or HTML via a JavaScript expression, as demonstrated by the onload attribute of a BODY element located after a check-host-alive! sequence, a different vulnerability than CVE-2011-2179.

    Published: 14 Jun 2011
    4.3
    Medium

    CVE-2010-4667

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.4.27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Jun 2011
    8.2
    High

    CVE-2011-1857

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote authenticated users to bypass intended access restrictions via unknown vectors.

    Published: 14 Jun 2011
    4.3
    Medium

    CVE-2011-1862

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Jun 2011
    5
    Medium

    CVE-2011-1924

    Last Modified: 11 Apr 2025

    Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory authority crash) via a crafted policy that triggers creation of a long port list.

    Published: 14 Jun 2011
    9.3
    Critical

    CVE-2011-2094

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2095 and CVE-2011-2097.

    Published: 14 Jun 2011
    9.3
    Critical

    CVE-2011-2097

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2094 and CVE-2011-2095.

    Published: 14 Jun 2011
    9.3
    Critical

    CVE-2011-2098

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2099.

    Published: 14 Jun 2011
    9.3
    Critical

    CVE-2011-2099

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2098.

    Published: 14 Jun 2011
    9.3
    Critical

    CVE-2011-2101

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X do not properly restrict script, which allows attackers to execute arbitrary code via a crafted document, related to a "cross document script execution vulnerability."

    Published: 14 Jun 2011
    9.3
    Critical

    CVE-2011-2105

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted font data.

    Published: 14 Jun 2011
    9.3
    Critical

    CVE-2011-2096

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.

    Published: 14 Jun 2011
    9.3
    Critical

    CVE-2011-2095

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2094 and CVE-2011-2097.

    Published: 14 Jun 2011
    4.3
    Medium

    CVE-2011-2104

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to cause a denial of service (memory corruption) via unspecified vectors.

    Published: 14 Jun 2011
    10
    Critical

    CVE-2011-2110

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in June 2011.

    Published: 14 Jun 2011
    6.4
    Medium

    CVE-2011-2202

    Last Modified: 11 Apr 2025

    The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."

    Published: 12 Jun 2011
    3.3
    Low

    CVE-2011-2533

    Last Modified: 11 Apr 2025

    The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.

    Published: 10 Jun 2011
    7.5
    High

    CVE-2011-2199

    Last Modified: 11 Apr 2025

    Buffer overflow in tftp-hpa before 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the utimeout option.

    Published: 10 Jun 2011
    9.3
    Critical

    CVE-2011-1708

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs cookie.

    Published: 9 Jun 2011
    5
    Medium

    CVE-2011-2474

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path.

    Published: 9 Jun 2011
    10
    Critical

    CVE-2011-2475

    Last Modified: 11 Apr 2025

    Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybase OneBridge Mobile Data Suite 5.5 and 5.6 allows remote attackers to execute arbitrary code via format string specifiers in unspecified string fields, related to authentication logging.

    Published: 9 Jun 2011
    9.3
    Critical

    CVE-2011-1699

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted uri parameter in a printer-url.

    Published: 9 Jun 2011
    9.3
    Critical

    CVE-2011-1702

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted file-date-time parameter in a printer-url.

    Published: 9 Jun 2011
    9.3
    Critical

    CVE-2011-1703

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted driver-version parameter in a printer-url.

    Published: 9 Jun 2011
    9.3
    Critical

    CVE-2011-1704

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted core-package parameter in a printer-url.

    Published: 9 Jun 2011
    9.3
    Critical

    CVE-2011-1706

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted iprint-client-config-info parameter in a printer-url.

    Published: 9 Jun 2011
    4.3
    Medium

    CVE-2011-1810

    Last Modified: 11 Apr 2025

    The Cascading Style Sheets (CSS) implementation in Google Chrome before 12.0.742.91 does not properly restrict access to the visit history, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 9 Jun 2011
    4.3
    Medium

    CVE-2011-1811

    Last Modified: 11 Apr 2025

    Google Chrome before 12.0.742.91 does not properly handle a large number of form submissions, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 9 Jun 2011
    7.5
    High

    CVE-2011-1812

    Last Modified: 11 Apr 2025

    Google Chrome before 12.0.742.91 allows remote attackers to bypass intended access restrictions via vectors related to extensions.

    Published: 9 Jun 2011
    6.8
    Medium

    CVE-2011-1813

    Last Modified: 11 Apr 2025

    Google Chrome before 12.0.742.91 does not properly implement the framework for extensions, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 9 Jun 2011
    5.8
    Medium

    CVE-2011-1814

    Last Modified: 11 Apr 2025

    Google Chrome before 12.0.742.91 attempts to read data from an uninitialized pointer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 9 Jun 2011
    4.3
    Medium

    CVE-2011-1815

    Last Modified: 11 Apr 2025

    Google Chrome before 12.0.742.91 allows remote attackers to inject script into a tab page via vectors related to extensions.

    Published: 9 Jun 2011
    6.8
    Medium

    CVE-2011-1816

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the developer tools in Google Chrome before 12.0.742.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 9 Jun 2011
    4.3
    Medium

    CVE-2011-1819

    Last Modified: 11 Apr 2025

    Google Chrome before 12.0.742.91 allows remote attackers to perform unspecified injection into a chrome:// page via vectors related to extensions.

    Published: 9 Jun 2011
    7.5
    High

    CVE-2011-2332

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 12.0.742.91, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 9 Jun 2011
    4.3
    Medium

    CVE-2011-2342

    Last Modified: 11 Apr 2025

    The DOM implementation in Google Chrome before 12.0.742.91 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 9 Jun 2011
    9.3
    Critical

    CVE-2011-1701

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted profile-name parameter in a printer-url.

    Published: 9 Jun 2011
    9.3
    Critical

    CVE-2011-1705

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted client-file-name parameter in a printer-url.

    Published: 9 Jun 2011
    9.3
    Critical

    CVE-2011-1707

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs parameter in a printer-url.

    Published: 9 Jun 2011
    6.8
    Medium

    CVE-2011-1809

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the accessibility feature in Google Chrome before 12.0.742.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 9 Jun 2011
    6.8
    Medium

    CVE-2011-1818

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the image loader in Google Chrome before 12.0.742.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 9 Jun 2011
    9.3
    Critical

    CVE-2011-1700

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted profile-time parameter in a printer-url.

    Published: 9 Jun 2011
    6.8
    Medium

    CVE-2011-1808

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 12.0.742.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to incorrect integer calculations during float handling.

    Published: 9 Jun 2011