CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2011-1308

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Installation Verification Test (IVT) application in the Install component in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Mar 2011
    1.9
    Low

    CVE-2011-1310

    Last Modified: 11 Apr 2025

    The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, which allows local users to obtain potentially sensitive information by reading these files.

    Published: 8 Mar 2011
    4
    Medium

    CVE-2011-1319

    Last Modified: 11 Apr 2025

    The Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15 allows remote authenticated users to cause a denial of service (memory consumption) by using a Lightweight Third-Party Authentication (LTPA) token for authentication.

    Published: 8 Mar 2011
    5.7
    Medium

    CVE-2011-0714

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 might allow remote attackers to cause a denial of service (crash) via malformed data in a packet, related to lockd and the svc_xprt_received function.

    Published: 8 Mar 2011
    2.1
    Low

    CVE-2011-1160

    Last Modified: 11 Apr 2025

    The tpm_open function in drivers/char/tpm/tpm.c in the Linux kernel before 2.6.39 does not initialize a certain buffer, which allows local users to obtain potentially sensitive information from kernel memory via unspecified vectors.

    Published: 8 Mar 2011
    4.3
    Medium

    CVE-2011-0633

    Last Modified: 11 Apr 2025

    The Net::HTTPS module in libwww-perl (LWP) before 6.00, as used in WWW::Mechanize, LWP::UserAgent, and other products, when running in environments that do not set the If-SSL-Cert-Subject header, does not enable full validation of SSL certificates by default, which allows remote attackers to spoof servers via man-in-the-middle (MITM) attacks involving hostnames that are not properly validated. NOTE: it could be argued that this is a design limitation of the Net::HTTPS API, and separate implementations should be independently assigned CVE identifiers for not working around this limitation. However, because this API was modified within LWP, a single CVE identifier has been assigned.

    Published: 8 Mar 2011
    5.8
    Medium

    CVE-2011-1429

    Last Modified: 11 Apr 2025

    Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

    Published: 8 Mar 2011
    4.3
    Medium

    CVE-2012-2639

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4940. Reason: This candidate is a reservation duplicate of CVE-2011-4940. Notes: All CVE users should reference CVE-2011-4940 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 8 Mar 2011
    7.5
    High

    CVE-2011-1092

    Last Modified: 11 Apr 2025

    Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive memory via a large third argument to the shmop_read function.

    Published: 8 Mar 2011
    2.1
    Low

    CVE-2011-1162

    Last Modified: 11 Apr 2025

    The tpm_read function in the Linux kernel 2.6 does not properly clear memory, which might allow local users to read the results of the previous TPM command.

    Published: 8 Mar 2011
    2.6
    Low

    CVE-2011-4940

    Last Modified: 11 Apr 2025

    The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.

    Published: 8 Mar 2011
    6.8
    Medium

    CVE-2009-3028

    Last Modified: 11 Apr 2025

    The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.

    Published: 7 Mar 2011
    7.5
    High

    CVE-2011-0434

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Domain Technologie Control (DTC) before 0.32.9 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) admin/bw_per_month.php or (2) client/bw_per_month.php.

    Published: 7 Mar 2011
    5
    Medium

    CVE-2011-0435

    Last Modified: 11 Apr 2025

    Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which allows remote attackers to obtain potentially sensitive bandwidth information via a direct request.

    Published: 7 Mar 2011
    5
    Medium

    CVE-2011-0436

    Last Modified: 11 Apr 2025

    The register_user function in client/new_account_form.php in Domain Technologie Control (DTC) before 0.32.9 includes a cleartext password in an e-mail message, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

    Published: 7 Mar 2011
    4
    Medium

    CVE-2011-0437

    Last Modified: 11 Apr 2025

    shared/inc/sql/ssh.php in the SSH accounts management implementation in Domain Technologie Control (DTC) before 0.32.9 allows remote authenticated users to delete arbitrary accounts via the edssh_account parameter in a deletesshaccount Delete action.

    Published: 7 Mar 2011
    2.1
    Low

    CVE-2011-0279

    Last Modified: 11 Apr 2025

    HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via actions that were intended to require authentication.

    Published: 7 Mar 2011
    6.5
    Medium

    CVE-2011-3363

    Last Modified: 11 Apr 2025

    The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share.

    Published: 7 Mar 2011
    3.6
    Low

    CVE-2012-3355

    Last Modified: 11 Apr 2025

    (1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory.

    Published: 6 Mar 2011
    4.9
    Medium

    CVE-2011-1090

    Last Modified: 11 Apr 2025

    The __nfs4_proc_set_acl function in fs/nfs/nfs4proc.c in the Linux kernel before 2.6.38 stores NFSv4 ACL data in memory that is allocated by kmalloc but not properly freed, which allows local users to cause a denial of service (panic) via a crafted attempt to set an ACL.

    Published: 5 Mar 2011
    6.8
    Medium

    CVE-2011-0411

    Last Modified: 11 Apr 2025

    The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

    Published: 5 Mar 2011
    1.9
    Low

    CVE-2011-1073

    Last Modified: 11 Apr 2025

    crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum comparisons on arbitrary pairs of files via two symlink attacks on /tmp/crontab.XXXXXXXXXX temporary files.

    Published: 4 Mar 2011
    1.9
    Low

    CVE-2011-1074

    Last Modified: 11 Apr 2025

    crontab.c in crontab in FreeBSD allows local users to determine the existence of arbitrary directories via a command-line argument composed of a directory name concatenated with a directory traversal sequence that leads to the /etc/crontab pathname.

    Published: 4 Mar 2011
    6.8
    Medium

    CVE-2011-5244

    Last Modified: 11 Apr 2025

    Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.

    Published: 4 Mar 2011
    7.6
    High

    CVE-2011-0116

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the setOuterText method in the htmlelement library in WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to DOM manipulations during iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0118

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0120

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0121

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0122

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0123

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0124

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0126

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0127

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0128

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0129

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0130

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0131

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0134

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0135

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0136

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0137

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0139

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0140

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0141

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0142

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0143

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0144

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0147

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0148

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0150

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011