CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2011-1900

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary code via an invalid request.

    Published: 4 May 2011
    5.8
    Medium

    CVE-2011-1826

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the Administrative Console in CA Arcot WebFort Versatile Authentication Server (VAS) before 6.2.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 4 May 2011
    9.3
    Critical

    CVE-2011-0340

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.

    Published: 4 May 2011
    4.3
    Medium

    CVE-2011-1209

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.17 uses a weak WS-Security XML encryption algorithm, which makes it easier for remote attackers to obtain plaintext data from a (1) JAX-RPC or (2) JAX-WS Web Services request via unspecified vectors related to a "decryption attack."

    Published: 4 May 2011
    4.3
    Medium

    CVE-2011-1825

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Administrative Console in CA Arcot WebFort Versatile Authentication Server (VAS) before 6.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 May 2011
    9.8
    Critical

    CVE-2011-4973

    Last Modified: 21 Nov 2024

    Authentication bypass vulnerability in mod_nss 1.0.8 allows remote attackers to assume the identity of a valid user by using their certificate and entering 'password' as the password.

    Published: 4 May 2011
    5.8
    Medium

    CVE-2011-1775

    Last Modified: 11 Apr 2025

    The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.

    Published: 4 May 2011
    6.8
    Medium

    CVE-2011-1434

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not ensure thread safety during handling of MIME data, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 3 May 2011
    5
    Medium

    CVE-2011-1435

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not properly implement the tabs permission for extensions, which allows remote attackers to read local files via a crafted extension.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1437

    Last Modified: 11 Apr 2025

    Multiple integer overflows in Google Chrome before 11.0.696.57 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float rendering.

    Published: 3 May 2011
    7.5
    High

    CVE-2011-1438

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 allows remote attackers to bypass the Same Origin Policy via vectors involving blobs.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1439

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 on Linux does not properly isolate renderer processes, which has unspecified impact and remote attack vectors.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1441

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not properly perform a cast of an unspecified variable during handling of floating select lists, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted HTML document.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1442

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not properly handle mutation events, which allows remote attackers to cause a denial of service (node tree corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1443

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not properly implement layering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."

    Published: 3 May 2011
    5.8
    Medium

    CVE-2011-1446

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 allows remote attackers to spoof the URL bar via vectors involving (1) a navigation error or (2) an interrupted load.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1447

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not properly handle drop-down lists, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1448

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not properly perform height calculations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1449

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the WebSockets implementation in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1454

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the DOM id handling functionality in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document.

    Published: 3 May 2011
    7.8
    High

    CVE-2011-1605

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su2, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCth39586.

    Published: 3 May 2011
    7.8
    High

    CVE-2011-1606

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCtg62855.

    Published: 3 May 2011
    6.5
    Medium

    CVE-2011-1607

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote authenticated users to upload files to arbitrary directories via a modified pathname in an upload request, aka Bug ID CSCti81603.

    Published: 3 May 2011
    8.5
    High

    CVE-2011-1609

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtg85647.

    Published: 3 May 2011
    7.8
    High

    CVE-2011-1785

    Last Modified: 11 Apr 2025

    VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.

    Published: 3 May 2011
    5
    Medium

    CVE-2011-1786

    Last Modified: 11 Apr 2025

    lsassd in Likewise Open /Enterprise 5.3 before build 7845, Open 6.0 before build 8325, and Enterprise 6.0 before build 178, as distributed in VMware ESXi 4.1 and ESX 4.1 and possibly other products, allows remote attackers to cause a denial of service (daemon crash) via an Active Directory login attempt that provides a username containing an invalid byte sequence.

    Published: 3 May 2011
    7.5
    High

    CVE-2011-1303

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not properly handle floating objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 3 May 2011
    5
    Medium

    CVE-2011-1304

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to bypass the pop-up blocker via vectors related to plug-ins.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1445

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not properly handle SVG documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 3 May 2011
    7.5
    High

    CVE-2011-1451

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not properly handle DOM id maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "dangling pointers."

    Published: 3 May 2011
    5.8
    Medium

    CVE-2011-1452

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 allows user-assisted remote attackers to spoof the URL bar via vectors involving a redirect and a manual reload.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1456

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not properly handle PDF forms, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."

    Published: 3 May 2011
    7.1
    High

    CVE-2011-1604

    Last Modified: 11 Apr 2025

    Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (memory consumption and process failure) via a malformed SIP message, aka Bug ID CSCti42904.

    Published: 3 May 2011
    7.8
    High

    CVE-2011-1613

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 6.0 before 6.0.200.0, 7.0 before 7.0.98.216, and 7.0.1xx before 7.0.112.0 allows remote attackers to cause a denial of service (device reload) via a sequence of ICMP packets, aka Bug ID CSCth74426.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1305

    Last Modified: 11 Apr 2025

    Race condition in Google Chrome before 11.0.696.57 on Linux and Mac OS X allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to linked lists and a database.

    Published: 3 May 2011
    5
    Medium

    CVE-2011-1436

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 on Linux does not properly interact with the X Window System, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1440

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the ruby element and Cascading Style Sheets (CSS) token sequences.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1444

    Last Modified: 11 Apr 2025

    Race condition in the sandbox launcher implementation in Google Chrome before 11.0.696.57 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 3 May 2011
    5
    Medium

    CVE-2011-1450

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not properly present file dialogs, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "dangling pointers."

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1455

    Last Modified: 11 Apr 2025

    Google Chrome before 11.0.696.57 does not properly handle PDF documents with multipart encoding, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.

    Published: 3 May 2011
    6.4
    Medium

    CVE-2011-1610

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or (3) n parameter, aka Bug ID CSCtj42064.

    Published: 3 May 2011
    7.5
    High

    CVE-2011-1522

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the Doctrine\DBAL\Platforms\AbstractPlatform::modifyLimitQuery function in Doctrine 1.x before 1.2.4 and 2.x before 2.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset field.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1684

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the MP4_ReadBox_skcr function in libmp4.c in the MP4 demultiplexer in VideoLAN VLC media player 1.x before 1.1.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted MP4 file.

    Published: 3 May 2011
    4.3
    Medium

    CVE-2011-1727

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13, 11.01, and 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an "HTML injection" issue.

    Published: 3 May 2011
    4.3
    Medium

    CVE-2011-1739

    Last Modified: 11 Apr 2025

    The makemask function in mountd.c in mountd in FreeBSD 7.4 through 8.2 does not properly handle a -network field specifying a CIDR block with a prefix length that is not an integer multiple of 8, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances via an NFS mount request.

    Published: 3 May 2011
    6.5
    Medium

    CVE-2011-1846

    Last Modified: 11 Apr 2025

    IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authenticated users to execute non-DDL statements by leveraging previous inherited possession of a role, a different vulnerability than CVE-2011-0757. NOTE: some of these details are obtained from third party information.

    Published: 3 May 2011
    4.3
    Medium

    CVE-2011-1726

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13, 11.01, and 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 May 2011
    4.9
    Medium

    CVE-2011-1847

    Last Modified: 11 Apr 2025

    IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly enforce privilege requirements for table access, which allows remote authenticated users to modify SYSSTAT.TABLES statistics columns via an UPDATE statement. NOTE: some of these details are obtained from third party information.

    Published: 3 May 2011
    7.6
    High

    CVE-2011-1087

    Last Modified: 11 Apr 2025

    Buffer overflow in VideoLAN VLC media player 1.0.5 allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .mp3 file that is played during bookmark creation.

    Published: 3 May 2011
    4.9
    Medium

    CVE-2011-1538

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in HP Proliant Support Pack (PSP) before 8.7 allows remote authenticated users to redirect other users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 3 May 2011