CVE Feed

    Dashboard / CVE

    7.6
    High

    CVE-2011-0151

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    5.1
    Medium

    CVE-2011-0154

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows and Apple iOS, does not properly implement the .sort function for JavaScript arrays, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0155

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0156

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    9.3
    Critical

    CVE-2011-0170

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted International Color Consortium (ICC) profile in a JPEG image.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0114

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0115

    Last Modified: 11 Apr 2025

    The DOM level 2 implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, does not properly handle DOM manipulations associated with event listeners during processing of range objects, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0117

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0125

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0132

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the Runin box functionality in the Cascading Style Sheets (CSS) 2.1 Visual Formatting Model implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0133

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly access glyph data during layout actions for floating blocks associated with pseudo-elements, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0146

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0153

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0165

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0111

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0112

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0113

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0119

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0138

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0145

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0149

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly parse HTML elements associated with document namespaces, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to a "dangling pointer" and iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0152

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0164

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    7.6
    High

    CVE-2011-0168

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

    Published: 3 Mar 2011
    4.3
    Medium

    CVE-2011-0715

    Last Modified: 11 Apr 2025

    The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.

    Published: 3 Mar 2011
    3.3
    Low

    CVE-2011-1675

    Last Modified: 11 Apr 2025

    mount in util-linux 2.19 and earlier attempts to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.

    Published: 3 Mar 2011
    3.3
    Low

    CVE-2011-1676

    Last Modified: 11 Apr 2025

    mount in util-linux 2.19 and earlier does not remove the /etc/mtab.tmp file after a failed attempt to add a mount entry, which allows local users to trigger corruption of the /etc/mtab file via multiple invocations.

    Published: 3 Mar 2011
    4.6
    Medium

    CVE-2011-1677

    Last Modified: 11 Apr 2025

    mount in util-linux 2.19 and earlier does not remove the /etc/mtab~ lock file after a failed attempt to add a mount entry, which has unspecified impact and local attack vectors.

    Published: 3 Mar 2011
    3.3
    Low

    CVE-2011-1678

    Last Modified: 11 Apr 2025

    smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the /etc/mtab file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.

    Published: 3 Mar 2011
    7.1
    High

    CVE-2011-4326

    Last Modified: 11 Apr 2025

    The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device.

    Published: 3 Mar 2011
    4.3
    Medium

    CVE-2011-0455

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Things BBS before 2.0.3 and BBS Thread before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Mar 2011
    7.2
    High

    CVE-2011-1006

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 allows local users to gain privileges via a crafted controller list on the command line of an application. NOTE: it is not clear whether this issue crosses privilege boundaries.

    Published: 3 Mar 2011
    3.3
    Low

    CVE-2011-1089

    Last Modified: 11 Apr 2025

    The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.

    Published: 3 Mar 2011
    4
    Medium

    CVE-2010-4754

    Last Modified: 11 Apr 2025

    The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

    Published: 2 Mar 2011
    4.9
    Medium

    CVE-2011-1023

    Last Modified: 11 Apr 2025

    The Reliable Datagram Sockets (RDS) subsystem in the Linux kernel before 2.6.38 does not properly handle congestion map updates, which allows local users to cause a denial of service (BUG_ON and system crash) via vectors involving (1) a loopback (aka loop) transmit operation or (2) an InfiniBand (aka ib) transmit operation.

    Published: 2 Mar 2011
    5.8
    Medium

    CVE-2011-1088

    Last Modified: 11 Apr 2025

    Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.

    Published: 2 Mar 2011
    5.8
    Medium

    CVE-2011-1183

    Last Modified: 11 Apr 2025

    Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.

    Published: 2 Mar 2011
    4.3
    Medium

    CVE-2011-1582

    Last Modified: 11 Apr 2025

    Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.

    Published: 2 Mar 2011
    9.3
    Critical

    CVE-2011-0191

    Last Modified: 11 Apr 2025

    Buffer overflow in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with JPEG encoding.

    Published: 2 Mar 2011
    9.3
    Critical

    CVE-2011-0192

    Last Modified: 11 Apr 2025

    Buffer overflow in Fax4Decode in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF Internet Fax image file that has been compressed using CCITT Group 4 encoding, related to the EXPAND2D macro in libtiff/tif_fax3.h. NOTE: some of these details are obtained from third party information.

    Published: 2 Mar 2011
    7.8
    High

    CVE-2011-1093

    Last Modified: 11 Apr 2025

    The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before 2.6.38 does not properly handle packets for a CLOSED endpoint, which allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending a DCCP-Close packet followed by a DCCP-Reset packet.

    Published: 2 Mar 2011
    6.9
    Medium

    CVE-2011-1146

    Last Modified: 11 Apr 2025

    libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.

    Published: 2 Mar 2011
    5.8
    Medium

    CVE-2011-1419

    Last Modified: 11 Apr 2025

    Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.

    Published: 2 Mar 2011
    4.3
    Medium

    CVE-2011-0278

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Web Jetadmin 10.2 Service Release 3 and 4 allows local users to bypass intended access restrictions via unknown vectors.

    Published: 1 Mar 2011
    7.2
    High

    CVE-2011-1017

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table.

    Published: 1 Mar 2011
    4.3
    Medium

    CVE-2011-1106

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to inject arbitrary web script or HTML via the authReasonCode parameter in an OpenDatabase action.

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1109

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) stylesheets, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1110

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly implement key frame rules, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1111

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly implement forms controls, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1112

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly perform SVG rendering, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.

    Published: 1 Mar 2011