CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2011-1414

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the tibbr web server, as used in TIBCO tibbr 1.0.0 through 1.5.0 and tibbr Service 1.0.0 through 1.5.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Mar 2011
    10
    Critical

    CVE-2011-1505

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.27 services for Lotus Domino has unknown impact and attack vectors, aka SPR ESEO8DQME2.

    Published: 22 Mar 2011
    3.5
    Low

    CVE-2008-7284

    Last Modified: 11 Apr 2025

    IBM Lotus Quickr 8.1 before 8100.003 services for Lotus Domino allows remote authenticated users to cause a denial of service (daemon crash) by clicking a download link, aka SPR QCAO7E6AM8.

    Published: 22 Mar 2011
    5
    Medium

    CVE-2008-7285

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the docnote string handling implementation in IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, aka SPR JFLD7GZT25.

    Published: 22 Mar 2011
    3.5
    Low

    CVE-2009-5062

    Last Modified: 11 Apr 2025

    IBM Lotus Quickr 8.1 before 8.1.0.15 services for Lotus Domino on AIX allows remote authenticated users to cause a denial of service (daemon crash) by subscribing to an Atom feed, aka SPR JRIE7VKMP9.

    Published: 22 Mar 2011
    6.8
    Medium

    CVE-2011-0759

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration page in the Recaptcha (aka WP-reCAPTCHA) plugin 2.9.8.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that disable the CAPTCHA requirement or insert cross-site scripting (XSS) sequences via the (1) recaptcha_opt_pubkey, (2) recaptcha_opt_privkey, (3) re_tabindex, (4) error_blank, (5) error_incorrect, (6) mailhide_pub, (7) mailhide_priv, (8) mh_replace_link, or (9) mh_replace_title parameter.

    Published: 22 Mar 2011
    6.8
    Medium

    CVE-2011-1506

    Last Modified: 11 Apr 2025

    The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411. NOTE: some of these details are obtained from third party information.

    Published: 22 Mar 2011
    5
    Medium

    CVE-2010-1674

    Last Modified: 11 Apr 2025

    The extended-community parser in bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed Extended Communities attribute.

    Published: 21 Mar 2011
    5
    Medium

    CVE-2010-1675

    Last Modified: 11 Apr 2025

    bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (session reset) via a malformed AS_PATHLIMIT path attribute.

    Published: 21 Mar 2011
    6.8
    Medium

    CVE-2011-1167

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value.

    Published: 21 Mar 2011
    9.3
    Critical

    CVE-2011-0024

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted capture file.

    Published: 21 Mar 2011
    5
    Medium

    CVE-2011-1465

    Last Modified: 11 Apr 2025

    The SPDY implementation in net/http/http_network_transaction.cc in Google Chrome before 11.0.696.14 drains the bodies from SPDY responses, which might allow remote SPDY servers to cause a denial of service (application exit) by canceling a stream.

    Published: 20 Mar 2011
    5
    Medium

    CVE-2011-1027

    Last Modified: 11 Apr 2025

    Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characters, as demonstrated by a %gg sequence.

    Published: 20 Mar 2011
    7.8
    High

    CVE-2011-4913

    Last Modified: 11 Apr 2025

    The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.

    Published: 20 Mar 2011
    6.4
    Medium

    CVE-2011-4914

    Last Modified: 11 Apr 2025

    The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a ROSE socket.

    Published: 20 Mar 2011
    7.5
    High

    CVE-2011-1493

    Last Modified: 11 Apr 2025

    Array index error in the rose_parse_national function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by composing FAC_NATIONAL_DIGIS data that specifies a large number of digipeaters, and then sending this data to a ROSE socket.

    Published: 20 Mar 2011
    4.9
    Medium

    CVE-2011-2521

    Last Modified: 11 Apr 2025

    The x86_assign_hw_event function in arch/x86/kernel/cpu/perf_event.c in the Performance Events subsystem in the Linux kernel before 2.6.39 does not properly calculate counter values, which allows local users to cause a denial of service (panic) via the perf program.

    Published: 19 Mar 2011
    1.9
    Low

    CVE-2011-2693

    Last Modified: 11 Apr 2025

    The perf subsystem in the kernel package 2.6.32-122.el6.x86_64 in Red Hat Enterprise Linux (RHEL) 6 does not properly handle NMIs, which might allow local users to cause a denial of service (excessive log messages) via unspecified vectors.

    Published: 19 Mar 2011
    4.3
    Medium

    CVE-2008-7275

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) before 2.3.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) AgentTicketMailbox or (2) CustomerTicketOverView.

    Published: 18 Mar 2011
    5
    Medium

    CVE-2008-7278

    Last Modified: 11 Apr 2025

    The S/MIME feature in Open Ticket Request System (OTRS) before 2.2.5, and 2.3.x before 2.3.0-beta1, does not properly configure the RANDFILE environment variable for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.

    Published: 18 Mar 2011
    6.5
    Medium

    CVE-2008-7279

    Last Modified: 11 Apr 2025

    The CustomerInterface component in Open Ticket Request System (OTRS) before 2.2.8 allows remote authenticated users to bypass intended access restrictions and access tickets of arbitrary customers via unspecified vectors.

    Published: 18 Mar 2011
    5
    Medium

    CVE-2008-7280

    Last Modified: 11 Apr 2025

    Kernel/System/EmailParser.pm in PostmasterPOP3.pl in Open Ticket Request System (OTRS) before 2.2.7 does not properly handle e-mail messages containing malformed UTF-8 characters, which allows remote attackers to cause a denial of service (e-mail retrieval outage) via a crafted message.

    Published: 18 Mar 2011
    4.3
    Medium

    CVE-2008-7281

    Last Modified: 11 Apr 2025

    Open Ticket Request System (OTRS) before 2.2.7 sends e-mail containing a Bcc header field that lists the Blind Carbon Copy recipients, which allows remote attackers to obtain potentially sensitive e-mail address information by reading this field.

    Published: 18 Mar 2011
    4.6
    Medium

    CVE-2008-7282

    Last Modified: 11 Apr 2025

    Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm in Open Ticket Request System (OTRS) before 2.2.6, when the CustomerPanelOwnSelection and CustomerGroupSupport options are enabled, allows remote authenticated users to bypass intended access restrictions, and perform certain (1) list and (2) write operations on queues, via unspecified vectors.

    Published: 18 Mar 2011
    2.1
    Low

    CVE-2009-5056

    Last Modified: 11 Apr 2025

    Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then selecting the ticket from the watched-tickets list.

    Published: 18 Mar 2011
    5
    Medium

    CVE-2009-5057

    Last Modified: 11 Apr 2025

    The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.

    Published: 18 Mar 2011
    1.9
    Low

    CVE-2010-4758

    Last Modified: 11 Apr 2025

    installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.

    Published: 18 Mar 2011
    4
    Medium

    CVE-2010-4759

    Last Modified: 11 Apr 2025

    Open Ticket Request System (OTRS) before 3.0.0-beta7 does not properly restrict the ticket ages that are within the scope of a search, which allows remote authenticated users to cause a denial of service (daemon hang) via a fulltext search.

    Published: 18 Mar 2011
    3.5
    Low

    CVE-2010-4760

    Last Modified: 11 Apr 2025

    Open Ticket Request System (OTRS) before 3.0.0-beta6 adds email-notification-ext articles to tickets during processing of event-based notifications, which allows remote authenticated users to obtain potentially sensitive information by reading a ticket.

    Published: 18 Mar 2011
    6.5
    Medium

    CVE-2010-4763

    Last Modified: 11 Apr 2025

    The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.

    Published: 18 Mar 2011
    5
    Medium

    CVE-2010-4764

    Last Modified: 11 Apr 2025

    Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it easier for remote attackers to spoof e-mail communication by leveraging a key that has a revocation signature.

    Published: 18 Mar 2011
    4.9
    Medium

    CVE-2010-4765

    Last Modified: 11 Apr 2025

    Race condition in the Kernel::System::Main::FileWrite method in Open Ticket Request System (OTRS) before 2.4.8 allows remote authenticated users to corrupt the TicketCounter.log data in opportunistic circumstances by creating tickets.

    Published: 18 Mar 2011
    4.3
    Medium

    CVE-2010-4766

    Last Modified: 11 Apr 2025

    The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially sensitive image information in opportunistic circumstances by reading a forwarded message in a standard e-mail client.

    Published: 18 Mar 2011
    5
    Medium

    CVE-2010-4767

    Last Modified: 11 Apr 2025

    Open Ticket Request System (OTRS) before 2.3.6 does not properly handle e-mail messages in which the From line contains UTF-8 characters associated with diacritical marks and an invalid charset, which allows remote attackers to cause a denial of service (duplicate tickets and duplicate auto-responses) by sending a crafted message to a POP3 mailbox.

    Published: 18 Mar 2011
    6
    Medium

    CVE-2010-4768

    Last Modified: 11 Apr 2025

    Open Ticket Request System (OTRS) before 2.3.5 does not properly disable hidden permissions, which allows remote authenticated users to bypass intended queue access restrictions in opportunistic circumstances by visiting a ticket, related to a certain ordering of permission-set and permission-remove operations involving both hidden permissions and other permissions.

    Published: 18 Mar 2011
    5
    Medium

    CVE-2011-1433

    Last Modified: 11 Apr 2025

    The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the session data in the database, which makes it easier for context-dependent attackers to obtain sensitive information by reading the _UserLogin and _UserPW fields.

    Published: 18 Mar 2011
    6.5
    Medium

    CVE-2008-7277

    Last Modified: 11 Apr 2025

    Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.

    Published: 18 Mar 2011
    3.5
    Low

    CVE-2010-4762

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the rich-text-editor component in Open Ticket Request System (OTRS) before 3.0.0-beta2 allows remote authenticated users to inject arbitrary web script or HTML by using the "source code" feature in the customer interface.

    Published: 18 Mar 2011
    4.6
    Medium

    CVE-2008-7276

    Last Modified: 11 Apr 2025

    Kernel/System/Web/Request.pm in Open Ticket Request System (OTRS) before 2.3.2 creates a directory under /tmp/ with 1274 permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations, related to incorrect interpretation of 0700 as a decimal value.

    Published: 18 Mar 2011
    6
    Medium

    CVE-2008-7283

    Last Modified: 11 Apr 2025

    Open Ticket Request System (OTRS) before 2.2.6, when customer group support is enabled, allows remote authenticated users to bypass intended access restrictions and perform web-interface updates to tickets by leveraging queue read permissions.

    Published: 18 Mar 2011
    3.5
    Low

    CVE-2009-5055

    Last Modified: 11 Apr 2025

    Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2.

    Published: 18 Mar 2011
    4
    Medium

    CVE-2010-4761

    Last Modified: 11 Apr 2025

    The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog.

    Published: 18 Mar 2011
    6.8
    Medium

    CVE-2011-2716

    Last Modified: 11 Apr 2025

    The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.

    Published: 18 Mar 2011
    7.2
    High

    CVE-2011-1169

    Last Modified: 11 Apr 2025

    Array index error in the asihpi_hpi_ioctl function in sound/pci/asihpi/hpioctl.c in the AudioScience HPI driver in the Linux kernel before 2.6.38.1 might allow local users to cause a denial of service (memory corruption) or possibly gain privileges via a crafted adapter index value that triggers access to an invalid kernel pointer.

    Published: 17 Mar 2011
    7.5
    High

    CVE-2011-0322

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in EMC RSA Access Manager Server 5.5.x, 6.0.x, and 6.1.x allows remote attackers to access resources via unknown vectors.

    Published: 16 Mar 2011
    3.5
    Low

    CVE-2011-0442

    Last Modified: 11 Apr 2025

    The service utility in EMC Avamar 5.x before 5.0.4 uses cleartext to transmit event details in (1) service requests and (2) e-mail messages, which might allow remote attackers to obtain sensitive information by sniffing the network.

    Published: 16 Mar 2011
    8.5
    High

    CVE-2011-0648

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in EMC Avamar before 5.0.4-30 allows remote authenticated users to gain privileges via unknown vectors.

    Published: 16 Mar 2011
    4
    Medium

    CVE-2011-0745

    Last Modified: 11 Apr 2025

    SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain duplicate check, which allows remote authenticated users to discover (1) the names of customers via a ShowDuplicates action to the Accounts module, reachable through index.php; or (2) the names of contact persons via a ShowDuplicates action to the Contacts module, reachable through index.php.

    Published: 16 Mar 2011
    7.5
    High

    CVE-2011-0751

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in nhttpd (aka Nostromo webserver) before 1.9.4 allows remote attackers to execute arbitrary programs or read arbitrary files via a ..%2f (encoded dot dot slash) in a URI.

    Published: 16 Mar 2011
    10
    Critical

    CVE-2011-0889

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Client Automation Enterprise (aka HPCA or Radia Notify) 5.11, 7.2, 7.5, 7.8, and 7.9 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 16 Mar 2011