CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2011-1113

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 on 64-bit Linux platforms does not properly perform pickle deserialization, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1114

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."

    Published: 1 Mar 2011
    6.8
    Medium

    CVE-2011-1118

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly handle TEXTAREA elements, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1119

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly determine device orientation, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 1 Mar 2011
    5
    Medium

    CVE-2011-1120

    Last Modified: 11 Apr 2025

    The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, aka Issue 71717.

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1121

    Last Modified: 11 Apr 2025

    Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a TEXTAREA element.

    Published: 1 Mar 2011
    5
    Medium

    CVE-2011-1122

    Last Modified: 11 Apr 2025

    The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, aka Issue 71960.

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1125

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly perform layout, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 1 Mar 2011
    8.3
    High

    CVE-2011-0454

    Last Modified: 11 Apr 2025

    Buffer overflow in the PPP Access Concentrator (PPPAC) on the SEIL/x86 with firmware 1.00 through 1.61, SEIL/B1 with firmware 1.00 through 3.11, SEIL/X1 with firmware 1.00 through 3.11, SEIL/X2 with firmware 1.00 through 3.11, SEIL/Turbo with firmware 1.80 through 2.10, and SEIL/neu 2FE Plus with firmware 1.80 through 2.10 might allow remote attackers to execute arbitrary code via a PPPoE packet.

    Published: 1 Mar 2011
    4.9
    Medium

    CVE-2011-1012

    Last Modified: 11 Apr 2025

    The ldm_parse_vmdb function in fs/partitions/ldm.c in the Linux kernel before 2.6.38-rc6-git6 does not validate the VBLK size value in the VMDB structure in an LDM partition table, which allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted partition table.

    Published: 1 Mar 2011
    6.8
    Medium

    CVE-2011-1108

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly implement JavaScript dialogs, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1116

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly handle SVG animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1117

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly handle XHTML documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale nodes."

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1124

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to blocked plug-ins.

    Published: 1 Mar 2011
    4.3
    Medium

    CVE-2011-1107

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to spoof the URL bar via unknown vectors.

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1115

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1123

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, which has unspecified impact and remote attack vectors.

    Published: 1 Mar 2011
    4.3
    Medium

    CVE-2010-4747

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pluginurl parameter.

    Published: 1 Mar 2011
    4.3
    Medium

    CVE-2010-4748

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in pmwiki.php in PmWiki 2.2.20 allows remote attackers to inject arbitrary web script or HTML via the from parameter to Main/WikiSandbox. NOTE: some of these details are obtained from third party information.

    Published: 1 Mar 2011
    4.3
    Medium

    CVE-2010-4749

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) body parameter to action.php and the (2) amount and (3) action parameters to admin/index.php.

    Published: 1 Mar 2011
    6.8
    Medium

    CVE-2010-4750

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allows remote attackers to hijack the authentication of administrators.

    Published: 1 Mar 2011
    6
    Medium

    CVE-2010-4751

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the id parameter in an edituser action, a different vector than CVE-2008-6593, CVE-2010-3484, and CVE-2010-3485.

    Published: 1 Mar 2011
    6.8
    Medium

    CVE-2010-4752

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter, a different vector than CVE-2008-6593, CVE-2010-3484, and CVE-2010-3485. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Mar 2011
    4.3
    Medium

    CVE-2010-4753

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in LightNEasy.php in LightNEasy 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, which is not properly handled in a forced SQL error message.

    Published: 1 Mar 2011
    10
    Critical

    CVE-2011-0057

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the Web Workers implementation in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to execute arbitrary code via vectors related to a JavaScript Worker and garbage collection.

    Published: 1 Mar 2011
    6.8
    Medium

    CVE-2011-0064

    Last Modified: 11 Apr 2025

    The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.

    Published: 1 Mar 2011
    4
    Medium

    CVE-2011-0762

    Last Modified: 11 Apr 2025

    The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.

    Published: 1 Mar 2011
    4.3
    Medium

    CVE-2011-1138

    Last Modified: 11 Apr 2025

    Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remote attackers to cause a denial of service (application crash) via a malformed 6LoWPAN IPv6 packet.

    Published: 1 Mar 2011
    4.3
    Medium

    CVE-2011-1141

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-ldap.c in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (memory consumption) via (1) a long LDAP filter string or (2) an LDAP filter string containing many elements.

    Published: 1 Mar 2011
    7.5
    High

    CVE-2011-1142

    Last Modified: 11 Apr 2025

    Stack consumption vulnerability in the dissect_ber_choice function in the BER dissector in Wireshark 1.2.x through 1.2.15 and 1.4.x through 1.4.4 might allow remote attackers to cause a denial of service (infinite loop) via vectors involving self-referential ASN.1 CHOICE values.

    Published: 1 Mar 2011
    4.3
    Medium

    CVE-2011-1143

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file.

    Published: 1 Mar 2011
    6.8
    Medium

    CVE-2011-0051

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which makes it easier for remote attackers to force a user to respond positively to a dialog question, as demonstrated by a question about granting privileges.

    Published: 1 Mar 2011
    10
    Critical

    CVE-2011-0056

    Last Modified: 11 Apr 2025

    Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving exception timing and a large number of string values, aka an "atom map" issue.

    Published: 1 Mar 2011
    6.8
    Medium

    CVE-2011-0059

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site.

    Published: 1 Mar 2011
    10
    Critical

    CVE-2011-0062

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.14 and Thunderbird 3.1.x before 3.1.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 1 Mar 2011
    4.3
    Medium

    CVE-2011-1139

    Last Modified: 11 Apr 2025

    wiretap/pcapng.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (application crash) via a pcap-ng file that contains a large packet-length field.

    Published: 1 Mar 2011
    4.3
    Medium

    CVE-2011-1140

    Last Modified: 11 Apr 2025

    Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet.

    Published: 1 Mar 2011
    10
    Critical

    CVE-2011-0053

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 1 Mar 2011
    10
    Critical

    CVE-2011-0054

    Last Modified: 11 Apr 2025

    Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving non-local JavaScript variables, aka an "upvarMap" issue.

    Published: 1 Mar 2011
    10
    Critical

    CVE-2011-0055

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the JSON.stringify method in js3250.dll in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via unspecified vectors related to the js_HasOwnProperty function and garbage collection.

    Published: 1 Mar 2011
    10
    Critical

    CVE-2011-0058

    Last Modified: 11 Apr 2025

    Buffer overflow in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long string that triggers construction of a long text run.

    Published: 1 Mar 2011
    9.3
    Critical

    CVE-2011-0061

    Last Modified: 11 Apr 2025

    Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.

    Published: 1 Mar 2011
    6.8
    Medium

    CVE-2011-0188

    Last Modified: 11 Apr 2025

    The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."

    Published: 1 Mar 2011
    6.8
    Medium

    CVE-2011-1104

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Mutare EVM allow remote attackers to hijack the authentication of arbitrary users for requests that (1) change a PIN, (2) delete messages, (3) add a delivery address, or (4) change a delivery address.

    Published: 28 Feb 2011
    4.3
    Medium

    CVE-2011-1105

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Mutare EVM allow remote attackers to inject arbitrary web script or HTML via (1) a delivery address and possibly (2) a PIN.

    Published: 28 Feb 2011
    9.3
    Critical

    CVE-2011-0925

    Last Modified: 11 Apr 2025

    The CSDWebInstallerCtrl ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) allows remote attackers to download an unintended Cisco program onto a client machine, and execute this program, by identifying a Cisco program with a Cisco digital signature and then renaming this program to inst.exe, a different vulnerability than CVE-2010-0589 and CVE-2011-0926.

    Published: 28 Feb 2011
    2.1
    Low

    CVE-2011-1007

    Last Modified: 11 Apr 2025

    Best Practical Solutions RT before 3.8.9 does not perform certain redirect actions upon a login, which allows physically proximate attackers to obtain credentials by resubmitting the login form via the back button of a web browser on an unattended workstation after an RT logout.

    Published: 28 Feb 2011
    4
    Medium

    CVE-2011-1008

    Last Modified: 11 Apr 2025

    Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by custom-field value information, related to SQL logging.

    Published: 28 Feb 2011
    5
    Medium

    CVE-2011-0719

    Last Modified: 11 Apr 2025

    Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.

    Published: 28 Feb 2011
    10
    Critical

    CVE-2010-4227

    Last Modified: 11 Apr 2025

    The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, signed value in a NFS RPC request to port UDP 1234, leading to a stack-based buffer overflow.

    Published: 25 Feb 2011