CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2011-1666

    Last Modified: 11 Apr 2025

    Metaways Tine 2.0 allows remote attackers to obtain sensitive information via unknown vectors in (1) Crm/Controller.php, (2) Crm/Export/Csv.php, or (3) Calendar/Model/Attender.php, which reveal the full installation path.

    Published: 10 Apr 2011
    7.5
    High

    CVE-2011-1667

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Anzeigenmarkt 2011 allows remote attackers to execute arbitrary SQL commands via the q parameter in a list action.

    Published: 10 Apr 2011
    4.3
    Medium

    CVE-2011-1668

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 10 Apr 2011
    4.3
    Medium

    CVE-2011-1670

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the subject parameter to post_url/edit.

    Published: 10 Apr 2011
    5
    Medium

    CVE-2011-1665

    Last Modified: 11 Apr 2025

    PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain backup SQL files via a direct request for predictable filenames in cache/backup/.

    Published: 10 Apr 2011
    5
    Medium

    CVE-2011-1669

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary files via ..%2F (encoded dot dot) sequences in the url parameter.

    Published: 10 Apr 2011
    4.3
    Medium

    CVE-2011-0462

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the login page in the webui component in SUSE openSUSE Build Service (OBS) before 2.1.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Apr 2011
    7.5
    High

    CVE-2011-1663

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Translation Management module 6.x before 6.x-1.21 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 10 Apr 2011
    6.8
    Medium

    CVE-2011-1664

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Translation Management module 6.x before 6.x-1.21 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 10 Apr 2011
    4.3
    Medium

    CVE-2011-1671

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in app/controllers/todos_controller.rb in Tracks 1.7.2, 2.0RC2, and 2.0devel allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to todos/tag/. NOTE: some of these details are obtained from third party information.

    Published: 10 Apr 2011
    3.5
    Low

    CVE-2011-1491

    Last Modified: 11 Apr 2025

    The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then compose an e-mail message, related to a "login CSRF" issue.

    Published: 8 Apr 2011
    5.5
    Medium

    CVE-2011-1492

    Last Modified: 11 Apr 2025

    steps/utils/modcss.inc in Roundcube Webmail before 0.5.1 does not properly verify that a request is an expected request for an external Cascading Style Sheets (CSS) stylesheet, which allows remote authenticated users to trigger arbitrary outbound TCP connections from the server, and possibly obtain sensitive information, via a crafted request.

    Published: 8 Apr 2011
    10
    Critical

    CVE-2011-0285

    Last Modified: 11 Apr 2025

    The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.

    Published: 8 Apr 2011
    6.9
    Medium

    CVE-2011-4077

    Last Modified: 11 Apr 2025

    Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when CONFIG_XFS_DEBUG is disabled, allows local users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an XFS image containing a symbolic link with a long pathname.

    Published: 8 Apr 2011
    7.5
    High

    CVE-2010-4780

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the check_banlist function in includes/sessions.php in Enano CMS 1.1.7pl1; 1.0.6pl2; and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2 allows remote attackers to execute arbitrary SQL commands via the email parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 7 Apr 2011
    5
    Medium

    CVE-2010-4781

    Last Modified: 11 Apr 2025

    index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive information via a crafted title parameter, which reveals the installation path in an error message.

    Published: 7 Apr 2011
    7.5
    High

    CVE-2010-4782

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) city, (2) state, (3) country, (4) minprice, (5) maxprice, (6) bed, and (7) bath parameters, different vectors than CVE-2006-6807.

    Published: 7 Apr 2011
    2.6
    Low

    CVE-2010-4783

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) siteurl and (2) urlbanner parameters.

    Published: 7 Apr 2011
    4.3
    Medium

    CVE-2010-4779

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php in the WPtouch plugin 1.9.19.4 and 1.9.20 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wptouch_settings parameter to include/adsense-new.php. NOTE: some of these details are obtained from third party information.

    Published: 7 Apr 2011
    6.8
    Medium

    CVE-2010-4784

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in member.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Published: 7 Apr 2011
    5.1
    Medium

    CVE-2011-1179

    Last Modified: 11 Apr 2025

    The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer.

    Published: 7 Apr 2011
    4.9
    Medium

    CVE-2011-2496

    Last Modified: 11 Apr 2025

    Integer overflow in the vma_to_resize function in mm/mremap.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (BUG_ON and system crash) via a crafted mremap system call that expands a memory mapping.

    Published: 7 Apr 2011
    6.8
    Medium

    CVE-2011-1574

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in libmodplug before 0.8.8.2 allows remote attackers to execute arbitrary code via a crafted S3M file.

    Published: 7 Apr 2011
    3.3
    Low

    CVE-2011-0012

    Last Modified: 11 Apr 2025

    The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows local users to overwrite arbitrary files via a symlink attack on the usbrdrctl log file, which has a predictable name.

    Published: 7 Apr 2011
    4
    Medium

    CVE-2011-0895

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x and 8.1x allows remote authenticated users to obtain sensitive information via unknown vectors.

    Published: 6 Apr 2011
    5
    Medium

    CVE-2011-1652

    Last Modified: 11 Apr 2025

    The default configuration of Microsoft Windows 7 immediately prefers a new IPv6 and DHCPv6 service over a currently used IPv4 and DHCPv4 service upon receipt of an IPv6 Router Advertisement (RA), and does not provide an option to ignore an unexpected RA, which allows remote attackers to conduct man-in-the-middle attacks on communication with external IPv4 servers via vectors involving RAs, a DHCPv6 server, and NAT-PT on the local network, aka a "SLAAC Attack." NOTE: it can be argued that preferring IPv6 complies with RFC 3484, and that attempting to determine the legitimacy of an RA is currently outside the scope of recommended behavior of host operating systems

    Published: 6 Apr 2011
    9.3
    Critical

    CVE-2011-1525

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in rvrender.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted frame in an Internet Video Recording (IVR) file.

    Published: 6 Apr 2011
    5
    Medium

    CVE-2011-1475

    Last Modified: 11 Apr 2025

    The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

    Published: 6 Apr 2011
    6.1
    Medium

    CVE-2011-1497

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.

    Published: 6 Apr 2011
    4.3
    Medium

    CVE-2011-1558

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) 1.0.4 before FP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-1242.

    Published: 5 Apr 2011
    7.5
    High

    CVE-2011-1562

    Last Modified: 11 Apr 2025

    Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via unspecified vectors related to a crafted POST request. NOTE: some sources have reported this issue as SQL injection, but this might not be accurate.

    Published: 5 Apr 2011
    10
    Critical

    CVE-2011-1564

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via crafted (1) On_FC_MISC_FCS_MSGBROADCAST and (2) On_FC_MISC_FCS_MSGSEND packets, which trigger a heap-based buffer overflow.

    Published: 5 Apr 2011
    5
    Medium

    CVE-2011-1569

    Last Modified: 11 Apr 2025

    download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web root via (1) a trailing ".", (2) a trailing space, or (3) mixed case in the FileNameAttach parameter.

    Published: 5 Apr 2011
    6.8
    Medium

    CVE-2011-1561

    Last Modified: 11 Apr 2025

    The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentication via a login attempt with an arbitrary password.

    Published: 5 Apr 2011
    10
    Critical

    CVE-2011-1563

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via (1) a long username in an On_FC_CONNECT_FCS_LOGIN packet, and crafted (2) On_FC_CTAGLIST_FCS_CADDTAG, (3) On_FC_CTAGLIST_FCS_CDELTAG, (4) On_FC_CTAGLIST_FCS_ADDTAGMS, (5) On_FC_RFUSER_FCS_LOGIN, (6) unspecified "On_FC_BINFILE_FCS_*FILE", (7) On_FC_CGETTAG_FCS_GETTELEMETRY, (8) On_FC_CGETTAG_FCS_GETCHANNELTELEMETRY, (9) On_FC_CGETTAG_FCS_SETTELEMETRY, (10) On_FC_CGETTAG_FCS_SETCHANNELTELEMETRY, and (11) On_FC_SCRIPT_FCS_STARTPROG packets to port 910.

    Published: 5 Apr 2011
    10
    Critical

    CVE-2011-1566

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to execute arbitrary programs via ..\ (dot dot backslash) sequences in opcodes (1) 0xa and (2) 0x17 to TCP port 12397.

    Published: 5 Apr 2011
    10
    Critical

    CVE-2011-1568

    Last Modified: 11 Apr 2025

    Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated using the RMS Reports Delete command, related to the logging of messages to GSST.LOG. NOTE: some of these details are obtained from third party information.

    Published: 5 Apr 2011
    10
    Critical

    CVE-2011-1559

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the IBM Web Interface for Content Management (aka WEBi) 1.0.4 before FP3 has unknown impact and attack vectors.

    Published: 5 Apr 2011
    9.3
    Critical

    CVE-2011-1560

    Last Modified: 11 Apr 2025

    solid.exe in IBM solidDB before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6.5.x before 6.5.0.3 uses a password-hash length specified by the client, which allows remote attackers to bypass authentication via a short length value.

    Published: 5 Apr 2011
    10
    Critical

    CVE-2011-1565

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to (1) read (opcode 0x3) or (2) create or write (opcode 0x2) arbitrary files via ..\ (dot dot backslash) sequences to TCP port 12401.

    Published: 5 Apr 2011
    10
    Critical

    CVE-2011-1567

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted (1) ListAll, (2) Write File, (3) ReadFile, (4) Delete, (5) RenameFile, and (6) FileInfo commands in an 0xd opcode; (7) the Add, (8) ReadFile, (9) Write File, (10) Rename, (11) Delete, and (12) Add commands in an RMS report templates (0x7) opcode; and (13) 0x4 command in an STDREP request (0x8) opcode to TCP port 12401.

    Published: 5 Apr 2011
    9.3
    Critical

    CVE-2011-0465

    Last Modified: 11 Apr 2025

    xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message.

    Published: 5 Apr 2011
    7.8
    High

    CVE-2011-1771

    Last Modified: 11 Apr 2025

    The cifs_close function in fs/cifs/file.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (NULL pointer dereference and BUG) or possibly have unspecified other impact by setting the O_DIRECT flag during an attempt to open a file on a CIFS filesystem.

    Published: 5 Apr 2011
    7.5
    High

    CVE-2011-0997

    Last Modified: 11 Apr 2025

    dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.

    Published: 5 Apr 2011
    4.7
    Medium

    CVE-2011-1479

    Last Modified: 11 Apr 2025

    Double free vulnerability in the inotify subsystem in the Linux kernel before 2.6.39 allows local users to cause a denial of service (system crash) via vectors involving failed attempts to create files. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-4250.

    Published: 5 Apr 2011
    6.9
    Medium

    CVE-2011-1494

    Last Modified: 11 Apr 2025

    Integer overflow in the _ctl_do_mpt_command function in drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier might allow local users to gain privileges or cause a denial of service (memory corruption) via an ioctl call specifying a crafted value that triggers a heap-based buffer overflow.

    Published: 5 Apr 2011
    7.2
    High

    CVE-2011-1495

    Last Modified: 11 Apr 2025

    drivers/scsi/mpt2sas/mpt2sas_ctl.c in the Linux kernel 2.6.38 and earlier does not validate (1) length and (2) offset values before performing memory copy operations, which might allow local users to gain privileges, cause a denial of service (memory corruption), or obtain sensitive information from kernel memory via a crafted ioctl call, related to the _ctl_do_mpt_command and _ctl_diag_read_buffer functions.

    Published: 5 Apr 2011
    9.8
    Critical

    CVE-2011-2717

    Last Modified: 21 Nov 2024

    The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.

    Published: 5 Apr 2011
    4.4
    Medium

    CVE-2011-0891

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the OS-Core.CORE2-KRN fileset in HP HP-UX B.11.23 and B.11.31 allows local users to cause a denial of service via unknown vectors.

    Published: 3 Apr 2011
    4.3
    Medium

    CVE-2011-0893

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Operations 9.10 on UNIX platforms allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Apr 2011