CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-4793

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in detail.asp in Site2Nite Auto e-Manager allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 27 Apr 2011
    7.5
    High

    CVE-2010-4795

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ev_id parameter in a details action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 27 Apr 2011
    7.5
    High

    CVE-2010-4796

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in PHPYun 1.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) provinceid parameter to search.php and the (2) e parameter to resumeview.php.

    Published: 27 Apr 2011
    7.5
    High

    CVE-2010-4797

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.

    Published: 27 Apr 2011
    6.8
    Medium

    CVE-2010-4798

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the uri parameter.

    Published: 27 Apr 2011
    6.8
    Medium

    CVE-2010-4799

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Chipmunk Pwngame 1.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to authenticate.php and the (3) ID parameter to pwn.php. NOTE: some of these details are obtained from third party information.

    Published: 27 Apr 2011
    4.3
    Medium

    CVE-2011-1578

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.3, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .html at the end of the query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character.

    Published: 27 Apr 2011
    5.8
    Medium

    CVE-2011-1579

    Last Modified: 11 Apr 2025

    The checkCss function in includes/Sanitizer.php in the wikitext parser in MediaWiki before 1.16.3 does not properly validate Cascading Style Sheets (CSS) token sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information by using the \2f\2a and \2a\2f hex strings to surround CSS comments.

    Published: 27 Apr 2011
    4.3
    Medium

    CVE-2011-1587

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.4, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .html located before a ? (question mark) in a query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1578.

    Published: 27 Apr 2011
    9
    Critical

    CVE-2011-1599

    Last Modified: 11 Apr 2025

    manager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 does not properly check for the system privilege, which allows remote authenticated users to execute arbitrary commands via an Originate action that has an Async header in conjunction with an Application header.

    Published: 27 Apr 2011
    9.3
    Critical

    CVE-2011-1719

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the Web Viewer ActiveX controls in CA Output Management Web Viewer 11.0 and 11.5 allow remote attackers to execute arbitrary code via (1) a long SRC property value to the PPSViewer ActiveX control in PPSView.ocx before 1.0.0.7 or (2) a long Title property value to the UOMWV_Helper ActiveX control in UOMWV_HelperActiveX.ocx before 11.5.0.1.

    Published: 27 Apr 2011
    6
    Medium

    CVE-2010-4801

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in admin/updatelist.php in BaconMap 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filepath parameter.

    Published: 27 Apr 2011
    4.3
    Medium

    CVE-2011-1718

    Last Modified: 11 Apr 2025

    The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation attacks and gain privileges via crafted data.

    Published: 27 Apr 2011
    6.8
    Medium

    CVE-2010-2789

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in MediaWikiParserTest.php in MediaWiki 1.16 beta, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via unspecified vectors.

    Published: 27 Apr 2011
    6.4
    Medium

    CVE-2010-3260

    Last Modified: 11 Apr 2025

    oxf/xml/xerces/XercesSAXParserFactoryImpl.java in the xforms-server component in the XForms service in Orbeon Forms before 3.9 does not properly restrict DTDs in Ajax requests, which allows remote attackers to read arbitrary files or send HTTP requests to intranet servers via an entity declaration in conjunction with an entity reference, related to an "XML injection" issue.

    Published: 27 Apr 2011
    4.3
    Medium

    CVE-2010-4792

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in title.php in OPEN IT OverLook 5.0 allows remote attackers to inject arbitrary web script or HTML via the frame parameter.

    Published: 27 Apr 2011
    4.3
    Medium

    CVE-2010-4794

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in a jscalendar action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 27 Apr 2011
    7.5
    High

    CVE-2010-4800

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in doadd.php in BaconMap 1.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.

    Published: 27 Apr 2011
    5
    Medium

    CVE-2011-1507

    Last Modified: 11 Apr 2025

    Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 do not restrict the number of unauthenticated sessions to certain interfaces, which allows remote attackers to cause a denial of service (file descriptor exhaustion and disk space exhaustion) via a series of TCP connections.

    Published: 27 Apr 2011
    3.5
    Low

    CVE-2011-1580

    Last Modified: 11 Apr 2025

    The transwiki import functionality in MediaWiki before 1.16.3 does not properly check privileges, which allows remote authenticated users to perform imports from any wgImportSources wiki via a crafted POST request.

    Published: 27 Apr 2011
    5
    Medium

    CVE-2011-1725

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 27 Apr 2011
    7.2
    High

    CVE-2011-1760

    Last Modified: 11 Apr 2025

    utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to conduct eval injection attacks and gain privileges via shell metacharacters in the -e argument.

    Published: 26 Apr 2011
    6.3
    Medium

    CVE-2011-2472

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to overwrite arbitrary files via a .. (dot dot) in the --save argument, related to the --session-dir argument, a different vulnerability than CVE-2011-1760.

    Published: 26 Apr 2011
    6.3
    Medium

    CVE-2011-2473

    Last Modified: 11 Apr 2025

    The do_dump_data function in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to create or overwrite arbitrary files via a crafted --session-dir argument in conjunction with a symlink attack on the opd_pipe file, a different vulnerability than CVE-2011-1760.

    Published: 26 Apr 2011
    7.2
    High

    CVE-2011-2471

    Last Modified: 11 Apr 2025

    utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to gain privileges via shell metacharacters in the (1) --vmlinux, (2) --session-dir, or (3) --xen argument, related to the daemonrc file and the do_save_setup and do_load_setup functions, a different vulnerability than CVE-2011-1760.

    Published: 26 Apr 2011
    4.9
    Medium

    CVE-2011-2689

    Last Modified: 11 Apr 2025

    The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service (BUG and system crash) by arranging for all resource groups to have too little free space.

    Published: 26 Apr 2011
    6.9
    Medium

    CVE-2011-1421

    Last Modified: 11 Apr 2025

    EMC NetWorker 7.5.x before 7.5.4.3 and 7.6.x before 7.6.1.5, when the client push feature is enabled, uses weak permissions for an unspecified file, which allows local users to gain privileges via unknown vectors.

    Published: 22 Apr 2011
    6.5
    Medium

    CVE-2011-1534

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x allows remote authenticated users to obtain access to processes via unknown vectors.

    Published: 22 Apr 2011
    4.6
    Medium

    CVE-2011-1685

    Last Modified: 11 Apr 2025

    Best Practical Solutions RT 3.8.0 through 3.8.9 and 4.0.0rc through 4.0.0rc7, when the CustomFieldValuesSources (aka external custom field) option is enabled, allows remote authenticated users to execute arbitrary code via unspecified vectors, as demonstrated by a cross-site request forgery (CSRF) attack.

    Published: 22 Apr 2011
    4.3
    Medium

    CVE-2011-1688

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Best Practical Solutions RT 3.2.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allows remote attackers to read arbitrary files via a crafted HTTP request.

    Published: 22 Apr 2011
    4.3
    Medium

    CVE-2011-1689

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Apr 2011
    4.3
    Medium

    CVE-2011-1690

    Last Modified: 11 Apr 2025

    Best Practical Solutions RT 3.6.0 through 3.6.10 and 3.8.0 through 3.8.8 allows remote attackers to trick users into sending credentials to an arbitrary server via unspecified vectors.

    Published: 22 Apr 2011
    4
    Medium

    CVE-2011-1687

    Last Modified: 11 Apr 2025

    Best Practical Solutions RT 3.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allows remote authenticated users to obtain sensitive information by using the search interface, as demonstrated by retrieving encrypted passwords.

    Published: 22 Apr 2011
    4.3
    Medium

    CVE-2011-1422

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in EMC RSA Adaptive Authentication On-Premise (AAOP) 2.x, 5.7.x, and 6.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 22 Apr 2011
    6.5
    Medium

    CVE-2011-1686

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors, as demonstrated by reading data.

    Published: 22 Apr 2011
    5
    Medium

    CVE-2011-4905

    Last Modified: 11 Apr 2025

    Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.

    Published: 22 Apr 2011
    5
    Medium

    CVE-2008-7288

    Last Modified: 11 Apr 2025

    IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilization) via an anonymous DIGEST-MD5 LDAP Bind operation.

    Published: 21 Apr 2011
    4
    Medium

    CVE-2008-7290

    Last Modified: 11 Apr 2025

    Memory leak in the ldap_explode_rdn API function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allows remote authenticated users to cause a denial of service (memory consumption) by making many function calls.

    Published: 21 Apr 2011
    4
    Medium

    CVE-2009-5072

    Last Modified: 11 Apr 2025

    Memory leak in the ldap_explode_dn function in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.61 (aka 6.0.0.8-TIV-ITDS-IF0003) allows remote authenticated users to cause a denial of service (memory consumption) via an empty string argument.

    Published: 21 Apr 2011
    4
    Medium

    CVE-2009-5073

    Last Modified: 11 Apr 2025

    IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.59 (aka 6.0.0.8-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) by adding a nested group that contains the Distinguished Name (DN) of its parent entry.

    Published: 21 Apr 2011
    4
    Medium

    CVE-2010-4786

    Last Modified: 11 Apr 2025

    IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon crash or hang) via a paged search, as demonstrated by a certain idsldapsearch command, related to an improper ibm-slapdIdleTimeOut configuration setting.

    Published: 21 Apr 2011
    4
    Medium

    CVE-2010-4787

    Last Modified: 11 Apr 2025

    IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.63 (aka 6.0.0.8-TIV-ITDS-IF0005) allows remote authenticated users to cause a denial of service (daemon hang) via a paged search that triggers improper mutex processing.

    Published: 21 Apr 2011
    4
    Medium

    CVE-2010-4788

    Last Modified: 11 Apr 2025

    IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) does not perform certain locking of linked-list access, which allows remote authenticated users to cause a denial of service (daemon crash) via a paged search.

    Published: 21 Apr 2011
    4
    Medium

    CVE-2010-4789

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the proxy-server implementation in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.65 (aka 6.0.0.8-TIV-ITDS-IF0007) and 6.3 before 6.3.0.1 (aka 6.3.0.0-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (daemon crash) via a paged search that is interrupted by an LDAP Unbind operation.

    Published: 21 Apr 2011
    7.2
    High

    CVE-2011-1149

    Last Modified: 11 Apr 2025

    Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox and gain privileges, as demonstrated by psneuter and KillingInTheNameOf, related to the use of Android shared memory (ashmem) and ASHMEM_SET_PROT_MASK.

    Published: 21 Apr 2011
    10
    Critical

    CVE-2011-1206

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) allows remote attackers to execute arbitrary code via a crafted LDAP request. NOTE: some of these details are obtained from third party information.

    Published: 21 Apr 2011
    4
    Medium

    CVE-2011-1821

    Last Modified: 11 Apr 2025

    IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010 on Windows allows remote authenticated users to cause a denial of service (daemon hang) via a cn=changelog search.

    Published: 21 Apr 2011
    2.1
    Low

    CVE-2011-1822

    Last Modified: 11 Apr 2025

    The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local users to obtain sensitive information by reading this log.

    Published: 21 Apr 2011
    4
    Medium

    CVE-2008-7287

    Last Modified: 11 Apr 2025

    Multiple memory leaks in the (1) ldap_init and (2) ldap_url_search_direct API functions in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allow remote authenticated users to cause a denial of service (memory consumption) by making many function calls.

    Published: 21 Apr 2011
    4
    Medium

    CVE-2008-7289

    Last Modified: 11 Apr 2025

    IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords, which makes it easier for remote authenticated users to cause a denial of service (DB2 daemon deadlock) by making password changes that trigger updates to a DB2 password-history table.

    Published: 21 Apr 2011