CVE Feed

    Dashboard / CVE

    5.8
    Medium

    CVE-2011-0803

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 8.9 GA through 8.98.4.1, and OneWorld Tools through 24.1.3, allows remote attackers to affect integrity and availability, related to Enterprise Infrastructure SEC.

    Published: 20 Apr 2011
    3.6
    Low

    CVE-2011-0804

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 20 Apr 2011
    10
    Critical

    CVE-2011-0807

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Application Server 9.1, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Administration.

    Published: 20 Apr 2011
    4.3
    Medium

    CVE-2011-0809

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Web ADI component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors.

    Published: 20 Apr 2011
    4.3
    Medium

    CVE-2011-0785

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Help component in Oracle Database Server 11.1.0.7, 11.2.0.1, 11.2.0.2, 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, and 10.1.0.5; and Oracle Fusion Middleware 11.1.1.2.0, 11.1.1.3.0, and 11.1.1.4.0 allows remote attackers to affect integrity via unknown vectors.

    Published: 20 Apr 2011
    4.4
    Medium

    CVE-2011-0794

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5.0 allows local users to affect confidentiality, integrity, and availability, related to File ID SDK. NOTE: the previous information was obtained from the April 2011 CPU. Oracle has not commented on claims from a reliable third party that this issue is in (a) sccut.dll or (b) libsc_ut.so in Outside In 8.3.5.x through 8.3.5.5684, as used when using the CAB file identification functionality to parse OneNote (.onepkg) files and other formats.

    Published: 20 Apr 2011
    4.3
    Medium

    CVE-2011-0798

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 10.1.2.3 and 11.1.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Midtier Infrastructure.

    Published: 20 Apr 2011
    6.5
    Medium

    CVE-2011-0799

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Warehouse Builder component in Oracle Database Server 10.2.0.5 (OWB), 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Oracle Warehouse Builder User Account.

    Published: 20 Apr 2011
    5
    Medium

    CVE-2011-0806

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Network Foundation component in Oracle Database Server 10.1.0.5, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2, when running on Windows, allows remote attackers to affect availability via unknown vectors.

    Published: 20 Apr 2011
    4.3
    Medium

    CVE-2011-0789

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.

    Published: 20 Apr 2011
    4.3
    Medium

    CVE-2011-0791

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Data Export.

    Published: 20 Apr 2011
    2.1
    Low

    CVE-2011-0797

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Applications Install component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 20 Apr 2011
    4.3
    Medium

    CVE-2011-0805

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the UIX component in Oracle Database Server 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect integrity via unknown vectors.

    Published: 20 Apr 2011
    4.4
    Medium

    CVE-2011-0808

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.2.0 and 8.3.5.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Outside In Filters. NOTE: the previous information was obtained from the April 2011 CPU. Oracle has not commented on claims from a reliable third party that this issue is in (a) vswk6.dll or (b) libvs_wk6.so in Outside In 8.1.0.4037 through 8.3.5.5684, involving the Lotus 123 parser.

    Published: 20 Apr 2011
    6.8
    Medium

    CVE-2011-1484

    Last Modified: 11 Apr 2025

    jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application.

    Published: 20 Apr 2011
    4.9
    Medium

    CVE-2011-1598

    Last Modified: 11 Apr 2025

    The bcm_release function in net/can/bcm.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.

    Published: 20 Apr 2011
    4.9
    Medium

    CVE-2011-1748

    Last Modified: 11 Apr 2025

    The raw_release function in net/can/raw.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.

    Published: 20 Apr 2011
    2.1
    Low

    CVE-2011-0412

    Last Modified: 11 Apr 2025

    Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.

    Published: 19 Apr 2011
    4.3
    Medium

    CVE-2011-1721

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in php/partie_administrateur/administration.php in WebJaxe 1.02 allows remote attackers to hijack the authentication of administrators for requests that (1) modify passwords or (2) add new projects. NOTE: some of these details are obtained from third party information.

    Published: 19 Apr 2011
    4.3
    Medium

    CVE-2011-1723

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to projects/hg-helloworld/news/. NOTE: some of these details are obtained from third party information.

    Published: 19 Apr 2011
    7.5
    High

    CVE-2011-1722

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in WEC Discussion Forum (wec_discussion) extension 2.1.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in April 2011.

    Published: 19 Apr 2011
    10
    Critical

    CVE-2009-5071

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Palm Pre WebOS before 1.2.1 has unknown impact and attack vectors related to an "included contact template file."

    Published: 19 Apr 2011
    3.3
    Low

    CVE-2011-1749

    Last Modified: 12 Apr 2025

    The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.

    Published: 19 Apr 2011
    7.3
    High

    CVE-2011-3355

    Last Modified: 21 Nov 2024

    evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim.

    Published: 19 Apr 2011
    6.9
    Medium

    CVE-2011-1485

    Last Modified: 11 Apr 2025

    Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privileges by executing a setuid program from pkexec, related to the use of the effective user ID instead of the real user ID.

    Published: 19 Apr 2011
    4.6
    Medium

    CVE-2011-1496

    Last Modified: 11 Apr 2025

    tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a filename to the -S command-line option.

    Published: 18 Apr 2011
    4.3
    Medium

    CVE-2011-1518

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) 2.4.x before 2.4.10 and 3.x before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Apr 2011
    4.3
    Medium

    CVE-2011-1714

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in framework/source/resource/qx/test/jsonp_primitive.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to inject arbitrary web script or HTML via the callback parameter.

    Published: 18 Apr 2011
    5
    Medium

    CVE-2011-1715

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to read arbitrary files via ..%2f (encoded dot dot) sequences in the file parameter.

    Published: 18 Apr 2011
    4.3
    Medium

    CVE-2011-1716

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Xymon before 4.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Apr 2011
    9.3
    Critical

    CVE-2011-1426

    Last Modified: 11 Apr 2025

    The OpenURLInDefaultBrowser method in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and RealPlayer SP 1.0 through 1.1.5, launches a default handler for the filename specified in the first argument, which allows remote attackers to execute arbitrary code via a .rnx filename corresponding to a crafted RNX file.

    Published: 18 Apr 2011
    10
    Critical

    CVE-2010-4229

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in an unspecified servlet in the Inventory component in ZENworks Asset Management (ZAM) in Novell ZENworks Configuration Management 10.3 before 10.3.2, and 11, allows remote attackers to overwrite files, and subsequently execute arbitrary code, via directory traversal sequences in a filename field in an upload request.

    Published: 18 Apr 2011
    4.3
    Medium

    CVE-2011-0286

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in webdesktop/app in the BlackBerry Web Desktop Manager component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software before 5.0.2 MR5 and 5.0.3 before MR1, and BlackBerry Enterprise Server Express software 5.0.1 and 5.0.2, allows remote attackers to inject arbitrary web script or HTML via the displayErrorMessage parameter in a ManageDevices action.

    Published: 18 Apr 2011
    2.1
    Low

    CVE-2011-1717

    Last Modified: 11 Apr 2025

    Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone numbers, date of birth, instant message logs, and other private information.

    Published: 18 Apr 2011
    4.4
    Medium

    CVE-2011-0988

    Last Modified: 11 Apr 2025

    pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors.

    Published: 18 Apr 2011
    6.3
    Medium

    CVE-2011-0460

    Last Modified: 12 Apr 2025

    The init script in kbd, possibly 1.14.1 and earlier, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/defkeymap.map.

    Published: 18 Apr 2011
    4.3
    Medium

    CVE-2011-1595

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.

    Published: 18 Apr 2011
    4.3
    Medium

    CVE-2011-1713

    Last Modified: 11 Apr 2025

    Microsoft msxml.dll, as used in Internet Explorer 8 on Windows 7, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function. NOTE: this might overlap CVE-2011-1202.

    Published: 15 Apr 2011
    4.3
    Medium

    CVE-2011-0195

    Last Modified: 11 Apr 2025

    The generate-id XPath function in libxslt in Apple iOS 4.3.x before 4.3.2 allows remote attackers to obtain potentially sensitive information about heap memory addresses via a crafted web site. NOTE: this may overlap CVE-2011-1202.

    Published: 15 Apr 2011
    10
    Critical

    CVE-2011-1653

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attackers to execute arbitrary SQL commands via vectors involving the (1) UnAssignFunctionalRoles, (2) UnassignAdminRoles, (3) DeleteFilter, (4) NonAssignedUserList, (5) DeleteReportLayout, (6) DeleteReports, and (7) RegenerateReport stored procedures.

    Published: 15 Apr 2011
    7.5
    High

    CVE-2011-1654

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Heartbeat Web Service in CA.Itm.Server.ManagementWS.dll in the Management Server in CA Total Defense (TD) r12 before SE2 allows remote attackers to execute arbitrary code via directory traversal sequences in the GUID parameter in an upload request to FileUploadHandler.ashx.

    Published: 15 Apr 2011
    10
    Critical

    CVE-2011-1300

    Last Modified: 11 Apr 2025

    The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in libGLESv2.dll in the WebGLES library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox 4.x before 4.0.1 on Windows and in the GPU process in Google Chrome before 10.0.648.205 on Windows, allows remote attackers to execute arbitrary code via unspecified vectors, related to an "off-by-three" error.

    Published: 15 Apr 2011
    9.3
    Critical

    CVE-2011-1302

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the GPU process in Google Chrome before 10.0.648.205 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 15 Apr 2011
    7.5
    High

    CVE-2011-1655

    Last Modified: 11 Apr 2025

    The management.asmx module in the Management Web Service in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 sends a cleartext response to unspecified getDBConfigSettings requests, which makes it easier for remote attackers to obtain database credentials, and subsequently execute arbitrary code, by sniffing the network, related to the UNCWS Web Service.

    Published: 15 Apr 2011
    9.3
    Critical

    CVE-2011-1301

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the GPU process in Google Chrome before 10.0.648.205 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 15 Apr 2011
    5
    Medium

    CVE-2010-4563

    Last Modified: 11 Apr 2025

    The Linux kernel, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping.

    Published: 15 Apr 2011
    6.8
    Medium

    CVE-2011-0896

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP NFS/ONCplus B.11.31.10 and earlier on HP-UX B.11.31 allows remote authenticated users to cause a denial of service via unknown vectors.

    Published: 15 Apr 2011
    4.6
    Medium

    CVE-2011-0897

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.00 allows local users to read arbitrary files via unknown vectors.

    Published: 15 Apr 2011
    4.3
    Medium

    CVE-2011-0898

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.00 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Apr 2011
    4.3
    Medium

    CVE-2011-1531

    Last Modified: 11 Apr 2025

    The webscan component in the Embedded Web Server (EWS) on the HP Photosmart D110 and B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One, and C510; and ENVY 100 D410 printers allows remote attackers to read documents on the scan surface via unspecified vectors.

    Published: 15 Apr 2011