CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2011-2383

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing an http: URL that redirects to a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue, aka "Drag and Drop Information Disclosure Vulnerability." NOTE: this vulnerability exists because of an incomplete fix in the Internet Explorer 9 release.

    Published: 3 Jun 2011
    4.9
    Medium

    CVE-2011-2695

    Last Modified: 11 Apr 2025

    Multiple off-by-one errors in the ext4 subsystem in the Linux kernel before 3.0-rc5 allow local users to cause a denial of service (BUG_ON and system crash) by accessing a sparse file in extent format with a write operation involving a block number corresponding to the largest possible 32-bit unsigned integer.

    Published: 3 Jun 2011
    5
    Medium

    CVE-2009-4008

    Last Modified: 11 Apr 2025

    Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.

    Published: 2 Jun 2011
    9
    Critical

    CVE-2011-1220

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in lcfd.exe in Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 allows remote authenticated users to execute arbitrary code via a long opts field.

    Published: 2 Jun 2011
    10
    Critical

    CVE-2011-1623

    Last Modified: 11 Apr 2025

    Cisco Media Processing Software before 1.2 on Media Experience Engine (MXE) 5600 devices has a default root password, which makes it easier for context-dependent attackers to obtain access via (1) the local console, (2) an SSH session, or (3) a TELNET session, aka Bug ID CSCto77737.

    Published: 2 Jun 2011
    10
    Critical

    CVE-2011-2024

    Last Modified: 11 Apr 2025

    Cisco Network Registrar before 7.2 has a default administrative password, which makes it easier for remote attackers to obtain access via a TCP session, aka Bug ID CSCsm50627.

    Published: 2 Jun 2011
    6.8
    Medium

    CVE-2011-2328

    Last Modified: 11 Apr 2025

    Buffer overflow in HP LoadRunner allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a .usr (aka Virtual User script) file with long directives.

    Published: 2 Jun 2011
    9
    Critical

    CVE-2011-2330

    Last Modified: 11 Apr 2025

    Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 has an unspecified "built-in account" that is "trivially" accessed, which makes it easier for remote attackers to send requests to restricted pages via a session on TCP port 9495, a different vulnerability than CVE-2011-1220.

    Published: 2 Jun 2011
    10
    Critical

    CVE-2011-2331

    Last Modified: 11 Apr 2025

    Integer overflow in img.exe in HP Intelligent Management Center (IMC) allows remote attackers to execute arbitrary code via a crafted length value in an a packet that triggers a heap-based buffer overflow, possibly related to an "recv" field.

    Published: 2 Jun 2011
    6.6
    Medium

    CVE-2011-1602

    Last Modified: 11 Apr 2025

    The su utility on Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.0.3 allows local users to gain privileges via unspecified vectors, aka Bug ID CSCtf07426.

    Published: 2 Jun 2011
    6.6
    Medium

    CVE-2011-1603

    Last Modified: 11 Apr 2025

    Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 allow local users to gain privileges via unspecified vectors, aka Bug ID CSCtn65815.

    Published: 2 Jun 2011
    1.5
    Low

    CVE-2011-1637

    Last Modified: 11 Apr 2025

    Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962.

    Published: 2 Jun 2011
    6.5
    Medium

    CVE-2011-2329

    Last Modified: 11 Apr 2025

    The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration of timestamp tokens, which allows remote attackers to bypass intended access restrictions by leveraging an expired token, a different vulnerability than CVE-2011-0730.

    Published: 2 Jun 2011
    6.8
    Medium

    CVE-2011-1026

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hijack the authentication of administrators.

    Published: 2 Jun 2011
    4.3
    Medium

    CVE-2011-1077

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Jun 2011
    7.2
    High

    CVE-2011-2041

    Last Modified: 11 Apr 2025

    The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and on Windows Mobile, allows local users to gain privileges via unspecified user-interface interaction, aka Bug ID CSCta40556.

    Published: 2 Jun 2011
    6.5
    Medium

    CVE-2011-0730

    Last Modified: 11 Apr 2025

    Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.

    Published: 2 Jun 2011
    9.3
    Critical

    CVE-2011-2040

    Last Modified: 11 Apr 2025

    The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.5.3041, and 3.0.x before 3.0.629, on Linux and Mac OS X downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a Java applet, aka Bug ID CSCsy05934.

    Published: 2 Jun 2011
    7.6
    High

    CVE-2011-2039

    Last Modified: 11 Apr 2025

    The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a certain ActiveX control in vpnweb.ocx, aka Bug ID CSCsy00904.

    Published: 2 Jun 2011
    5
    Medium

    CVE-2011-0869

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 26 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to SAAJ.

    Published: 2 Jun 2011
    4
    Medium

    CVE-2011-2183

    Last Modified: 11 Apr 2025

    Race condition in the scan_get_next_rmap_item function in mm/ksm.c in the Linux kernel before 2.6.39.3, when Kernel SamePage Merging (KSM) is enabled, allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted application.

    Published: 2 Jun 2011
    4.3
    Medium

    CVE-2011-1921

    Last Modified: 11 Apr 2025

    The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.

    Published: 1 Jun 2011
    4.3
    Medium

    CVE-2011-1783

    Last Modified: 11 Apr 2025

    The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memory consumption) in opportunistic circumstances by requesting data.

    Published: 1 Jun 2011
    4.9
    Medium

    CVE-2011-2213

    Last Modified: 11 Apr 2025

    The inet_diag_bc_audit function in net/ipv4/inet_diag.c in the Linux kernel before 2.6.39.3 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message, as demonstrated by an INET_DIAG_BC_JMP instruction with a zero yes value, a different vulnerability than CVE-2010-3880.

    Published: 1 Jun 2011
    5
    Medium

    CVE-2011-1752

    Last Modified: 11 Apr 2025

    The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.

    Published: 1 Jun 2011
    10
    Critical

    CVE-2011-2214

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Open Database Connectivity (ODBC) component in 7T Interactive Graphical SCADA System (IGSS) before 9.0.0.11143 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 20222, which triggers memory corruption related to an "invalid structure being used."

    Published: 31 May 2011
    7.8
    High

    CVE-2011-0943

    Last Modified: 11 Apr 2025

    Cisco IOS XR 3.8.3, 3.8.4, and 3.9.1 allows remote attackers to cause a denial of service (NetIO process restart or device reload) via a crafted IPv4 packet, aka Bug ID CSCth44147.

    Published: 31 May 2011
    7.8
    High

    CVE-2011-0949

    Last Modified: 11 Apr 2025

    Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.

    Published: 31 May 2011
    9.3
    Critical

    CVE-2011-1214

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a .rtf attachment, aka SPR PRAD8823JQ.

    Published: 31 May 2011
    9.3
    Critical

    CVE-2011-1216

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via crafted tag data in an Applix spreadsheet attachment, aka SPR PRAD8823A7.

    Published: 31 May 2011
    9.3
    Critical

    CVE-2011-1218

    Last Modified: 11 Apr 2025

    Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, aka SPR PRAD8E3NSP. NOTE: some of these details are obtained from third party information.

    Published: 31 May 2011
    9.3
    Critical

    CVE-2011-1512

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a malformed BIFF record in a .xls Excel spreadsheet attachment, aka SPR PRAD8E3HKR.

    Published: 31 May 2011
    9.3
    Critical

    CVE-2011-1645

    Last Modified: 11 Apr 2025

    The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote attackers to read the backup configuration file, and consequently execute arbitrary code, via unspecified vectors, aka Bug ID CSCtn23871.

    Published: 31 May 2011
    9
    Critical

    CVE-2011-1646

    Last Modified: 11 Apr 2025

    The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote authenticated users to execute arbitrary commands via the (1) ping test parameter or (2) traceroute test parameter, aka Bug ID CSCtn23871.

    Published: 31 May 2011
    5
    Medium

    CVE-2011-1647

    Last Modified: 11 Apr 2025

    The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote attackers to read the private key for the admin SSL certificate via unspecified vectors, aka Bug ID CSCtn23871.

    Published: 31 May 2011
    7.8
    High

    CVE-2011-1649

    Last Modified: 11 Apr 2025

    The Internet Streamer application in Cisco Content Delivery System (CDS) with software 2.5.7, 2.5.8, and 2.5.9 before build 126 allows remote attackers to cause a denial of service (Web Engine crash) via a crafted URL, aka Bug IDs CSCtg67333 and CSCth25341.

    Published: 31 May 2011
    4.3
    Medium

    CVE-2011-1922

    Last Modified: 11 Apr 2025

    daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.

    Published: 31 May 2011
    4.3
    Medium

    CVE-2011-1937

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Webmin 1.540 and earlier allows local users to inject arbitrary web script or HTML via a chfn command that changes the real (aka Full Name) field, related to useradmin/index.cgi and useradmin/user-lib.pl.

    Published: 31 May 2011
    7.5
    High

    CVE-2011-2215

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in WalRack 1.x before 1.1.8 and 2.x before 2.0.6 has unknown impact and attack vectors, possibly related to file deletion and an encoded URL, a different vulnerability than CVE-2011-1329.

    Published: 31 May 2011
    9.3
    Critical

    CVE-2011-1213

    Last Modified: 11 Apr 2025

    Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.

    Published: 31 May 2011
    9.3
    Critical

    CVE-2011-1215

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a Microsoft Office document attachment, aka SPR PRAD8823ND.

    Published: 31 May 2011
    9.3
    Critical

    CVE-2011-1217

    Last Modified: 11 Apr 2025

    Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .prz attachment. NOTE: some of these details are obtained from third party information.

    Published: 31 May 2011
    5
    Medium

    CVE-2011-1925

    Last Modified: 11 Apr 2025

    nbd-server.c in Network Block Device (nbd-server) 2.9.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by causing a negotiation failure, as demonstrated by specifying a name for a non-existent export.

    Published: 31 May 2011
    6.5
    Medium

    CVE-2011-0546

    Last Modified: 11 Apr 2025

    Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute NDMP commands via unspecified vectors.

    Published: 31 May 2011
    7.8
    High

    CVE-2011-0766

    Last Modified: 11 Apr 2025

    The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.

    Published: 31 May 2011
    6.8
    Medium

    CVE-2011-1329

    Last Modified: 11 Apr 2025

    WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads, which allows remote attackers to execute arbitrary PHP code via vectors involving a double extension, as demonstrated by a .php.zzz file.

    Published: 31 May 2011
    7.8
    High

    CVE-2011-1651

    Last Modified: 11 Apr 2025

    Cisco IOS XR 3.9.x and 4.0.x before 4.0.3 and 4.1.x before 4.1.1, when an SPA interface processor is installed, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 packet, aka Bug ID CSCto45095.

    Published: 31 May 2011
    7.5
    High

    CVE-2011-1755

    Last Modified: 11 Apr 2025

    jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Published: 31 May 2011
    4.3
    Medium

    CVE-2011-1948

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Plone 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 31 May 2011
    3.5
    Low

    CVE-2011-1949

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the safe_html filter in Products.PortalTransforms in Plone 2.1 through 4.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-2422.

    Published: 31 May 2011