CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2011-0894

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Operations 9.10 on UNIX platforms allows remote authenticated users to bypass intended access restrictions via unknown vectors.

    Published: 3 Apr 2011
    4.3
    Medium

    CVE-2010-3447

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in view.php in the file viewer in Horde Gollem before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the file parameter in a view_file action.

    Published: 1 Apr 2011
    4.3
    Medium

    CVE-2010-3693

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Horde Dynamic IMP (DIMP) before 1.1.5, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via vectors related to displaying mailbox names.

    Published: 1 Apr 2011
    9.3
    Critical

    CVE-2010-4596

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via a long string in an RTSP request.

    Published: 1 Apr 2011
    6.3
    Medium

    CVE-2011-0461

    Last Modified: 11 Apr 2025

    /etc/init.d/boot.localfs in the aaa_base package before 11.2-43.48.1 in SUSE openSUSE 11.2, and before 11.3-8.7.1 in openSUSE 11.3, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/mtab.

    Published: 1 Apr 2011
    6.9
    Medium

    CVE-2011-0468

    Last Modified: 11 Apr 2025

    The aaa_base package before 11.3-8.9.1 in SUSE openSUSE 11.3, and before 11.4-54.62.1 in openSUSE 11.4, allows local users to gain privileges via shell metacharacters in a filename, related to tab expansion.

    Published: 1 Apr 2011
    5
    Medium

    CVE-2011-0951

    Last Modified: 11 Apr 2025

    The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user passwords via unspecified vectors, aka Bug ID CSCtl77440.

    Published: 1 Apr 2011
    6.9
    Medium

    CVE-2011-1126

    Last Modified: 11 Apr 2025

    VMware vmrun, as used in VIX API 1.x before 1.10.3 and VMware Workstation 6.5.x and 7.x before 7.1.4 build 385536 on Linux, might allow local users to gain privileges via a Trojan horse shared library in an unspecified directory.

    Published: 1 Apr 2011
    6.8
    Medium

    CVE-2011-1556

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in plugins/pdfClasses/pdfgen.php in Andy's PHP Knowledgebase (Aphpkb) 0.95.4 allows remote attackers to execute arbitrary SQL commands via the pdfa parameter.

    Published: 1 Apr 2011
    7.5
    High

    CVE-2011-1557

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ICloudCenter ICJobSite 1.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter to an unspecified component, a different vulnerability than CVE-2011-1546. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Apr 2011
    4.3
    Medium

    CVE-2010-4778

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka fmusername), (2) password (aka fmpassword), or (3) server (aka fmserver) field in a fetchmail_prefs_save action, related to the Fetchmail configuration, a different issue than CVE-2010-3695. NOTE: some of these details are obtained from third party information.

    Published: 1 Apr 2011
    7.5
    High

    CVE-2011-1546

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.3 allow remote attackers to execute arbitrary SQL commands via the s parameter to (1) a_viewusers.php or (2) keysearch.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (3) id or (4) start parameter to pending.php, or the (5) aid parameter to a_authordetails.php. NOTE: some of these details are obtained from third party information.

    Published: 1 Apr 2011
    6.8
    Medium

    CVE-2011-1555

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in saa.php in Andy's PHP Knowledgebase (Aphpkb) 0.95.3 and earlier allows remote attackers to execute arbitrary SQL commands via the aid parameter, a different vulnerability than CVE-2011-1546. NOTE: some of these details are obtained from third party information.

    Published: 1 Apr 2011
    10
    Critical

    CVE-2010-4235

    Last Modified: 11 Apr 2025

    Format string vulnerability in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via vectors related to the x-wap-profile HTTP header.

    Published: 1 Apr 2011
    4.3
    Medium

    CVE-2010-3695

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via the fm_id parameter in a fetchmail_prefs_save action, related to the Fetchmail configuration.

    Published: 31 Mar 2011
    5
    Medium

    CVE-2011-0963

    Last Modified: 11 Apr 2025

    The default configuration of the RADIUS authentication feature on the Cisco Network Admission Control (NAC) Guest Server with software before 2.0.3 allows remote attackers to bypass intended access restrictions and obtain network connectivity via unspecified vectors, aka Bug ID CSCtj66922.

    Published: 31 Mar 2011
    5
    Medium

    CVE-2011-1174

    Last Modified: 11 Apr 2025

    manager.c in Asterisk Open Source 1.6.1.x before 1.6.1.24, 1.6.2.x before 1.6.2.17.2, and 1.8.x before 1.8.3.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a series of manager sessions involving invalid data.

    Published: 31 Mar 2011
    5
    Medium

    CVE-2011-1175

    Last Modified: 11 Apr 2025

    tcptls.c in the TCP/TLS server in Asterisk Open Source 1.6.1.x before 1.6.1.23, 1.6.2.x before 1.6.2.17.1, and 1.8.x before 1.8.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by establishing many short TCP sessions to services that use a certain TLS API.

    Published: 31 Mar 2011
    5.1
    Medium

    CVE-2011-1425

    Last Modified: 11 Apr 2025

    xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

    Published: 31 Mar 2011
    6.3
    Medium

    CVE-2011-1548

    Last Modified: 11 Apr 2025

    The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by /var/log/postgresql/.

    Published: 30 Mar 2011
    6.3
    Medium

    CVE-2011-1549

    Last Modified: 11 Apr 2025

    The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories under /var/log/ for packages.

    Published: 30 Mar 2011
    6.9
    Medium

    CVE-2011-1551

    Last Modified: 11 Apr 2025

    SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow local users to gain privileges by leveraging access to this account during root filesystem operations by the Cobbler daemon.

    Published: 30 Mar 2011
    6.3
    Medium

    CVE-2011-1550

    Last Modified: 11 Apr 2025

    The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories for the (1) cobbler, (2) inn, (3) safte-monitor, and (4) uucp packages.

    Published: 30 Mar 2011
    7.4
    High

    CVE-2011-1750

    Last Modified: 11 Apr 2025

    Multiple heap-based buffer overflows in the virtio-blk driver (hw/virtio-blk.c) in qemu-kvm 0.14.0 allow local guest users to cause a denial of service (guest crash) and possibly gain privileges via a (1) write request to the virtio_blk_handle_write function or (2) read request to the virtio_blk_handle_read function that is not properly aligned.

    Published: 30 Mar 2011
    5
    Medium

    CVE-2011-1487

    Last Modified: 11 Apr 2025

    The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

    Published: 30 Mar 2011
    6.3
    Medium

    CVE-2011-0441

    Last Modified: 11 Apr 2025

    The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php5/.

    Published: 29 Mar 2011
    3.5
    Low

    CVE-2011-0728

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view.

    Published: 29 Mar 2011
    4.3
    Medium

    CVE-2011-0892

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Diagnostics 7.5x and 8.0x before 8.05.54.225 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 29 Mar 2011
    4.3
    Medium

    CVE-2011-1176

    Last Modified: 11 Apr 2025

    The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.

    Published: 29 Mar 2011
    6.9
    Medium

    CVE-2011-1205

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1.4, ClearQuest 7.0.0.4 through 7.1.1.4, and other products allow local users to gain privileges via a Trojan horse HTML document in the My Computer zone.

    Published: 29 Mar 2011
    7.2
    High

    CVE-2011-1472

    Last Modified: 11 Apr 2025

    The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified button sequence at boot time.

    Published: 29 Mar 2011
    4.3
    Medium

    CVE-2011-1524

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to inject arbitrary web script or HTML via the username field, as demonstrated by injecting an IFRAME element into the event log, a different vulnerability than CVE-2011-0545.

    Published: 28 Mar 2011
    9.3
    Critical

    CVE-2010-3275

    Last Modified: 11 Apr 2025

    libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file, related to a "dangling pointer vulnerability."

    Published: 28 Mar 2011
    9.3
    Critical

    CVE-2010-3276

    Last Modified: 11 Apr 2025

    libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an NSV file.

    Published: 28 Mar 2011
    5.8
    Medium

    CVE-2011-0440

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that delete blogs.

    Published: 28 Mar 2011
    6.9
    Medium

    CVE-2011-0458

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.

    Published: 28 Mar 2011
    6.8
    Medium

    CVE-2011-0545

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts, and possibly have unspecified other impact, via the userRole parameter.

    Published: 28 Mar 2011
    4.3
    Medium

    CVE-2011-0439

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the Pieforms select box.

    Published: 28 Mar 2011
    4.3
    Medium

    CVE-2011-0760

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration screen in wp-relatedposts.php in the WP Related Posts plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences via the (1) wp_relatedposts_title, (2) wp_relatedposts_num, or (3) wp_relatedposts_type parameter.

    Published: 28 Mar 2011
    7.2
    High

    CVE-2011-1420

    Last Modified: 11 Apr 2025

    EMC Data Protection Advisor Collector 5.7 and 5.7.1 on Solaris SPARC platforms uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.

    Published: 28 Mar 2011
    6.9
    Medium

    CVE-2011-0727

    Last Modified: 11 Apr 2025

    GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.

    Published: 28 Mar 2011
    6.8
    Medium

    CVE-2011-0764

    Last Modified: 11 Apr 2025

    t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, uses an invalid pointer in conjunction with a dereference operation, which allows remote attackers to execute arbitrary code via a crafted Type 1 font in a PDF document, as demonstrated by testz.2184122398.pdf.

    Published: 28 Mar 2011
    4.3
    Medium

    CVE-2011-1554

    Last Modified: 11 Apr 2025

    Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.

    Published: 28 Mar 2011
    5.5
    Medium

    CVE-2011-3637

    Last Modified: 11 Apr 2025

    The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that trigger an m_start error.

    Published: 28 Mar 2011
    4.3
    Medium

    CVE-2011-1553

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory write, a different vulnerability than CVE-2011-0764.

    Published: 28 Mar 2011
    4.3
    Medium

    CVE-2011-1552

    Last Modified: 11 Apr 2025

    t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, reads from invalid memory locations, which allows remote attackers to cause a denial of service (application crash) via a crafted Type 1 font in a PDF document, a different vulnerability than CVE-2011-0764.

    Published: 28 Mar 2011
    7.5
    High

    CVE-2011-3359

    Last Modified: 11 Apr 2025

    The dma_rx function in drivers/net/wireless/b43/dma.c in the Linux kernel before 2.6.39 does not properly allocate receive buffers, which allows remote attackers to cause a denial of service (system crash) via a crafted frame.

    Published: 27 Mar 2011
    5.1
    Medium

    CVE-2011-1097

    Last Modified: 11 Apr 2025

    rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.

    Published: 26 Mar 2011
    7.5
    High

    CVE-2011-1293

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 25 Mar 2011
    7.5
    High

    CVE-2011-1294

    Last Modified: 11 Apr 2025

    Google Chrome before 10.0.648.204 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 25 Mar 2011