CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2011-1405

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Mahara before 1.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors associated with HTML e-mail messages, related to artefact/comment/lib.php and interaction/forum/lib.php.

    Published: 13 May 2011
    4.3
    Medium

    CVE-2011-1406

    Last Modified: 11 Apr 2025

    Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.

    Published: 13 May 2011
    4
    Medium

    CVE-2011-1404

    Last Modified: 11 Apr 2025

    Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.

    Published: 13 May 2011
    2.1
    Low

    CVE-2011-0995

    Last Modified: 11 Apr 2025

    The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.

    Published: 13 May 2011
    9.3
    Critical

    CVE-2011-1248

    Last Modified: 11 Apr 2025

    WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."

    Published: 13 May 2011
    9.3
    Critical

    CVE-2011-1269

    Last Modified: 11 Apr 2025

    Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 make unspecified function calls during file parsing without proper handling of memory, which allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Presentation Memory Corruption RCE Vulnerability."

    Published: 13 May 2011
    9.3
    Critical

    CVE-2011-1270

    Last Modified: 11 Apr 2025

    Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Presentation Buffer Overrun RCE Vulnerability."

    Published: 13 May 2011
    5.8
    Medium

    CVE-2011-1325

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in EC-CUBE before 2.11.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 13 May 2011
    7.2
    High

    CVE-2011-1738

    Last Modified: 11 Apr 2025

    HP Palm webOS 1.4.5 and 1.4.5.1 does not properly restrict Plug-in Development Kit (PDK) applications, which allows local users to gain privileges by leveraging unintended filesystem write access.

    Published: 13 May 2011
    10
    Critical

    CVE-2011-1849

    Last Modified: 11 Apr 2025

    tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to create or overwrite files, and subsequently execute arbitrary code, via a crafted WRQ request.

    Published: 13 May 2011
    10
    Critical

    CVE-2011-1850

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the logging functionality in dbman.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via vectors related to a received action.

    Published: 13 May 2011
    10
    Critical

    CVE-2011-1851

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a long mode field.

    Published: 13 May 2011
    10
    Critical

    CVE-2011-1852

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allow remote attackers to execute arbitrary code via crafted packet content accompanying a (1) DATA or (2) ERROR opcode.

    Published: 13 May 2011
    10
    Critical

    CVE-2011-1853

    Last Modified: 11 Apr 2025

    tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a (1) large or (2) invalid opcode field, related to a function pointer table.

    Published: 13 May 2011
    10
    Critical

    CVE-2011-1854

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a long syslog packet, related to an exception handler.

    Published: 13 May 2011
    4.3
    Medium

    CVE-2011-1855

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x allows local users to read or modify (1) log files or (2) other data via unknown vectors.

    Published: 13 May 2011
    9.3
    Critical

    CVE-2011-2089

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICONICS BizViz 9.x before 9.22 and GENESIS32 9.x before 9.22 allows remote attackers to execute arbitrary code via a long string in the argument. NOTE: some of these details are obtained from third party information.

    Published: 13 May 2011
    9.3
    Critical

    CVE-2011-0341

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the pdfmoz_onmouse function in apps/mozilla/moz_main.c in the MuPDF plug-in 2008.09.02 for Firefox allows remote attackers to execute arbitrary code via a crafted web site.

    Published: 13 May 2011
    4.3
    Medium

    CVE-2011-1737

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Email application in HP Palm webOS 1.4.5 and 1.4.5.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 May 2011
    2.1
    Low

    CVE-2011-1840

    Last Modified: 11 Apr 2025

    The MartiniCreations PassmanLite Password Manager application before 1.48 for Android stores the master password and unspecified other account information in cleartext, which allows local users to obtain sensitive information by leveraging shell access.

    Published: 13 May 2011
    10
    Critical

    CVE-2011-1848

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in img.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a crafted length field in a packet.

    Published: 13 May 2011
    8.8
    High

    CVE-2011-0627

    Last Modified: 23 Jun 2026

    Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.

    Published: 12 May 2011
    5
    Medium

    CVE-2011-0579

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to obtain sensitive information via unspecified vectors.

    Published: 12 May 2011
    9.3
    Critical

    CVE-2011-0621

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0619, CVE-2011-0620, and CVE-2011-0622.

    Published: 12 May 2011
    9.3
    Critical

    CVE-2011-0624

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code via unspecified vectors, related to a "bounds checking" issue, a different vulnerability than CVE-2011-0623, CVE-2011-0625, and CVE-2011-0626.

    Published: 12 May 2011
    9.3
    Critical

    CVE-2011-0625

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code via unspecified vectors, related to a "bounds checking" issue, a different vulnerability than CVE-2011-0623, CVE-2011-0624, and CVE-2011-0626.

    Published: 12 May 2011
    9.3
    Critical

    CVE-2011-0626

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code via unspecified vectors, related to a "bounds checking" issue, a different vulnerability than CVE-2011-0623, CVE-2011-0624, and CVE-2011-0625.

    Published: 12 May 2011
    9.3
    Critical

    CVE-2011-0628

    Last Modified: 11 Apr 2025

    Integer overflow in Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code via ActionScript that improperly handles a long array object.

    Published: 12 May 2011
    9.3
    Critical

    CVE-2011-0618

    Last Modified: 11 Apr 2025

    Integer overflow in Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code via unspecified vectors.

    Published: 12 May 2011
    9.3
    Critical

    CVE-2011-0619

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0620, CVE-2011-0621, and CVE-2011-0622.

    Published: 12 May 2011
    9.3
    Critical

    CVE-2011-0623

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code via unspecified vectors, related to a "bounds checking" issue, a different vulnerability than CVE-2011-0624, CVE-2011-0625, and CVE-2011-0626.

    Published: 12 May 2011
    9.3
    Critical

    CVE-2011-0620

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0619, CVE-2011-0621, and CVE-2011-0622.

    Published: 12 May 2011
    9.3
    Critical

    CVE-2011-0622

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0619, CVE-2011-0620, and CVE-2011-0621.

    Published: 12 May 2011
    3.6
    Low

    CVE-2011-2147

    Last Modified: 11 Apr 2025

    Openswan 2.2.x does not properly restrict permissions for (1) /var/run/starter.pid, related to starter.c in the IPsec starter, and (2) /var/lock/subsys/ipsec, which allows local users to kill arbitrary processes by writing a PID to a file, or possibly bypass disk quotas by writing arbitrary data to a file, as demonstrated by files with 0666 permissions, a different vulnerability than CVE-2011-1784.

    Published: 11 May 2011
    6.5
    Medium

    CVE-2011-2167

    Last Modified: 11 Apr 2025

    script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.

    Published: 11 May 2011
    1.2
    Low

    CVE-2011-1769

    Last Modified: 11 Apr 2025

    SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs context variable access.

    Published: 11 May 2011
    5
    Medium

    CVE-2011-1929

    Last Modified: 11 Apr 2025

    lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.

    Published: 11 May 2011
    6.5
    Medium

    CVE-2011-2166

    Last Modified: 11 Apr 2025

    script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

    Published: 11 May 2011
    1.2
    Low

    CVE-2011-1781

    Last Modified: 11 Apr 2025

    SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs stack unwinding (aka backtracing).

    Published: 11 May 2011
    7.5
    High

    CVE-2011-2077

    Last Modified: 11 Apr 2025

    The default configuration of the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier enables external TCP connections to port 10000, instead of connections only from 127.0.0.1, which makes it easier for remote attackers to have an unspecified impact via a TCP session.

    Published: 10 May 2011
    4.3
    Medium

    CVE-2011-2078

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 May 2011
    7.5
    High

    CVE-2011-2079

    Last Modified: 11 Apr 2025

    MediaCAST 8 and earlier allows remote attackers to have an unspecified impact via a (1) CP_RIGHTSOURCE or (2) bdclient_Inventive cookie to the default URI under inventivex/managetraining/, related to an "XML injection" issue.

    Published: 10 May 2011
    7.5
    High

    CVE-2011-2080

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in MediaCAST 8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) a CP_ENLARGESTYLE cookie to the default URI under inventivex/managetraining/ or (2) unspecified input to authenticate_ad_setup_finished.cfm.

    Published: 10 May 2011
    5
    Medium

    CVE-2010-0216

    Last Modified: 11 Apr 2025

    authenticate_ad_setup_finished.cfm in MediaCAST 8 and earlier allows remote attackers to discover usernames and cleartext passwords by reading the error messages returned for requests that use the UserID parameter.

    Published: 10 May 2011
    7.7
    High

    CVE-2011-1271

    Last Modified: 11 Apr 2025

    The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle expressions related to null strings, which allows context-dependent attackers to bypass intended access restrictions, and consequently execute arbitrary code, in opportunistic circumstances by leveraging a crafted application, as demonstrated by (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework JIT Optimization Vulnerability."

    Published: 10 May 2011
    5
    Medium

    CVE-2011-2076

    Last Modified: 11 Apr 2025

    MediaCAST 8 and earlier stores passwords in cleartext, which makes it easier for context-dependent attackers to obtain sensitive information by reading an unspecified password data store, a different vulnerability than CVE-2010-0216.

    Published: 10 May 2011
    5
    Medium

    CVE-2011-2081

    Last Modified: 11 Apr 2025

    MediaCAST 8 and earlier does not properly handle requests for inventivex/isptools/release/metadata/globalIncludeFolders.txt, which allows remote attackers to obtain sensitive information via unspecified vectors related to the Public/ directory tree.

    Published: 10 May 2011
    4.3
    Medium

    CVE-2011-1824

    Last Modified: 11 Apr 2025

    The VEGAOpBitmap::AddLine function in Opera before 10.61 does not properly initialize memory during processing of the SIZE attribute of a SELECT element, which allows remote attackers to trigger an invalid memory write operation, and consequently cause a denial of service (application crash) or possibly execute arbitrary code, via a large integer attribute value.

    Published: 10 May 2011
    8.5
    High

    CVE-2011-2074

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the client in Skype 5.x before 5.1.0.922 on Mac OS X allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via a crafted message.

    Published: 10 May 2011
    9.3
    Critical

    CVE-2011-2075

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome 11.0.696.65 on Windows 7 SP1 allows remote attackers to execute arbitrary code via unknown vectors. NOTE: as of 20110510, the only disclosure is a vague advisory that possibly relates to multiple vulnerabilities or multiple products. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 10 May 2011