CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2011-1539

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Proliant Support Pack (PSP) before 8.7 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 3 May 2011
    6
    Medium

    CVE-2011-1544

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Control Performance Management before 6.3 allows remote authenticated users to gain privileges via unknown vectors.

    Published: 3 May 2011
    6
    Medium

    CVE-2011-1724

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Virtual Server Environment before 6.3 allows remote authenticated users to gain privileges via unknown vectors.

    Published: 3 May 2011
    7.8
    High

    CVE-2011-1844

    Last Modified: 11 Apr 2025

    Memory leak in Microsoft Silverlight 4 before 4.0.60310.0 allows remote attackers to cause a denial of service (memory consumption) via an application involving a popup control and a custom DependencyProperty property, related to lack of garbage collection.

    Published: 3 May 2011
    9.3
    Critical

    CVE-2011-0610

    Last Modified: 11 Apr 2025

    The CoolType library in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 3 May 2011
    4.3
    Medium

    CVE-2011-1537

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Proliant Support Pack (PSP) before 8.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 May 2011
    7.8
    High

    CVE-2011-1845

    Last Modified: 11 Apr 2025

    Multiple memory leaks in the DataGrid control implementation in Microsoft Silverlight 4 before 4.0.60310.0 allow remote attackers to cause a denial of service (memory consumption) via an application involving (1) subscriptions to an INotifyDataErrorInfo.ErrorsChanged event or (2) a TextBlock or TextBox element.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1545

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 3 May 2011
    10
    Critical

    CVE-2009-5074

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MojoX::Dispatcher::Static implementation in Mojolicious before 0.991250 has unknown impact and attack vectors.

    Published: 3 May 2011
    10
    Critical

    CVE-2010-4802

    Last Modified: 11 Apr 2025

    Commands.pm in Mojolicious before 0.999928 does not properly perform CGI environment detection, which has unspecified impact and remote attack vectors.

    Published: 3 May 2011
    10
    Critical

    CVE-2010-4803

    Last Modified: 11 Apr 2025

    Mojolicious before 0.999927 does not properly implement HMAC-MD5 checksums, which has unspecified impact and remote attack vectors.

    Published: 3 May 2011
    6.8
    Medium

    CVE-2011-1843

    Last Modified: 11 Apr 2025

    Integer overflow in conf.c in Tinyproxy before 1.8.3 might allow remote attackers to bypass intended access restrictions in opportunistic circumstances via a TCP connection, related to improper handling of invalid port numbers.

    Published: 3 May 2011
    4.3
    Medium

    CVE-2011-1841

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the link_to helper in Mojolicious before 1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 May 2011
    7.2
    High

    CVE-2011-1842

    Last Modified: 11 Apr 2025

    dbus_backend/lsd.py in the D-Bus backend in language-selector before 0.6.7 does not validate the arguments to the (1) SetSystemDefaultLangEnv and (2) SetSystemDefaultLanguageEnv functions, which allows local users to gain privileges via shell metacharacters in a string argument, a different vulnerability than CVE-2011-0729.

    Published: 3 May 2011
    2.6
    Low

    CVE-2012-3368

    Last Modified: 11 Apr 2025

    Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an improper connection-close request, as demonstrated by running an IRC client in dtach.

    Published: 3 May 2011
    5
    Medium

    CVE-2011-0761

    Last Modified: 11 Apr 2025

    Perl 5.10.x allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an ability to inject arguments into a (1) getpeername, (2) readdir, (3) closedir, (4) getsockname, (5) rewinddir, (6) tell, or (7) telldir function call.

    Published: 3 May 2011
    3.5
    Low

    CVE-2011-0905

    Last Modified: 11 Apr 2025

    The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via crafted dimensions in a framebuffer update request that triggers an out-of-bounds read operation.

    Published: 2 May 2011
    3.5
    Low

    CVE-2011-0904

    Last Modified: 11 Apr 2025

    The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a denial of service (daemon crash) via a large (1) X position or (2) Y position value in a framebuffer update request that triggers an out-of-bounds memory access, related to the rfbTranslateNone and rfbSendRectEncodingRaw functions.

    Published: 2 May 2011
    7.2
    High

    CVE-2011-0729

    Last Modified: 11 Apr 2025

    dbus_backend/ls-dbus-backend in the D-Bus backend in language-selector before 0.6.7 does not restrict access on the basis of a PolicyKit check result, which allows local users to modify the /etc/default/locale and /etc/environment files via a (1) SetSystemDefaultLangEnv or (2) SetSystemDefaultLanguageEnv call.

    Published: 29 Apr 2011
    9
    Critical

    CVE-2011-1540

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote authenticated users to execute arbitrary code via unknown vectors.

    Published: 29 Apr 2011
    10
    Critical

    CVE-2011-1541

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote attackers to bypass intended access restrictions, and consequently execute arbitrary code, via unknown vectors.

    Published: 29 Apr 2011
    4.3
    Medium

    CVE-2011-1542

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Apr 2011
    4.3
    Medium

    CVE-2011-1543

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP Systems Insight Manager (SIM) before 6.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 29 Apr 2011
    5
    Medium

    CVE-2011-1589

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Path.pm in Mojolicious before 1.16 allows remote attackers to read arbitrary files via a %2f..%2f (encoded slash dot dot slash) in a URI.

    Published: 29 Apr 2011
    4.3
    Medium

    CVE-2011-1592

    Last Modified: 11 Apr 2025

    The NFS dissector in epan/dissectors/packet-nfs.c in Wireshark 1.4.x before 1.4.5 on Windows uses an incorrect integer data type during decoding of SETCLIENTID calls, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file.

    Published: 29 Apr 2011
    2.6
    Low

    CVE-2011-1499

    Last Modified: 11 Apr 2025

    acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy server.

    Published: 29 Apr 2011
    6
    Medium

    CVE-2011-1535

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Control for Linux (aka IC-Linux) before 6.3 allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

    Published: 29 Apr 2011
    5
    Medium

    CVE-2011-1536

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Performance Insight 5.0, 5.1x. 5.2x, 5.3x, 5.4, 5.41, and 5.41.002 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 29 Apr 2011
    6.9
    Medium

    CVE-2011-4355

    Last Modified: 11 Apr 2025

    GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.

    Published: 29 Apr 2011
    7.5
    High

    CVE-2011-1764

    Last Modified: 11 Apr 2025

    Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.

    Published: 29 Apr 2011
    5
    Medium

    CVE-2011-1839

    Last Modified: 11 Apr 2025

    IBM Rational Build Forge 7.1.0 uses the HTTP GET method during redirection from the authentication servlet to a PHP script, which makes it easier for context-dependent attackers to discover session IDs by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

    Published: 28 Apr 2011
    10
    Critical

    CVE-2011-0065

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel.

    Published: 28 Apr 2011
    10
    Critical

    CVE-2011-0066

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mObserverList.

    Published: 28 Apr 2011
    5
    Medium

    CVE-2011-0067

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly implement autocompletion for forms, which allows remote attackers to read form history entries via a Java applet that spoofs interaction with the autocomplete controls.

    Published: 28 Apr 2011
    5
    Medium

    CVE-2011-0071

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 on Windows allows remote attackers to determine the existence of arbitrary files, and possibly load resources, via vectors involving a resource: URL.

    Published: 28 Apr 2011
    10
    Critical

    CVE-2011-0072

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0074, CVE-2011-0075, CVE-2011-0077, and CVE-2011-0078.

    Published: 28 Apr 2011
    10
    Critical

    CVE-2011-0073

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."

    Published: 28 Apr 2011
    10
    Critical

    CVE-2011-0078

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, and CVE-2011-0077.

    Published: 28 Apr 2011
    10
    Critical

    CVE-2011-0080

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 28 Apr 2011
    10
    Critical

    CVE-2011-0081

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.17 and 4.x before 4.0.1, and Thunderbird 3.1.x before 3.1.10, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 28 Apr 2011
    10
    Critical

    CVE-2011-0069

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0070.

    Published: 28 Apr 2011
    10
    Critical

    CVE-2011-0070

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0069.

    Published: 28 Apr 2011
    10
    Critical

    CVE-2011-0075

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0077, and CVE-2011-0078.

    Published: 28 Apr 2011
    10
    Critical

    CVE-2011-0074

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0075, CVE-2011-0077, and CVE-2011-0078.

    Published: 28 Apr 2011
    10
    Critical

    CVE-2011-0077

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, and CVE-2011-0078.

    Published: 28 Apr 2011
    6.8
    Medium

    CVE-2011-1761

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ABC file. NOTE: some of these details are obtained from third party information.

    Published: 28 Apr 2011
    4.3
    Medium

    CVE-2010-2787

    Last Modified: 11 Apr 2025

    api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive information by retrieving documents from an HTTP proxy cache that has been used by a victim.

    Published: 27 Apr 2011
    2.6
    Low

    CVE-2010-2788

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in profileinfo.php in MediaWiki before 1.15.5, when wgEnableProfileInfo is enabled, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.

    Published: 27 Apr 2011
    5.8
    Medium

    CVE-2010-4790

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in FilterFTP 2.0.3, 2.0.5, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party information.

    Published: 27 Apr 2011
    7.5
    High

    CVE-2010-4791

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter.

    Published: 27 Apr 2011