CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2011-0332

    Last Modified: 11 Apr 2025

    Integer overflow in Foxit Reader before 4.3.1.0218 and Foxit Phantom before 2.3.3.1112 allows remote attackers to execute arbitrary code via crafted ICC chunks in a PDF file, which triggers a heap-based buffer overflow.

    Published: 25 Feb 2011
    6.8
    Medium

    CVE-2011-1101

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in a third-party component of the Citrix Licensing Administration Console 11.6, formerly License Management Console, allow remote attackers to (1) access unauthorized "license administration functionality" or (2) cause a denial of service via unknown vectors.

    Published: 25 Feb 2011
    4.3
    Medium

    CVE-2011-1102

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WebReporting module in F-Secure Policy Manager 7.x, 8.00 before hotfix 2, 8.1x before hotfix 3 on Windows and hotfix 2 on Linux, and 9.00 before hotfix 4 on Windows and hotfix 2 on Linux, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Feb 2011
    5
    Medium

    CVE-2011-1103

    Last Modified: 11 Apr 2025

    The WebReporting module in F-Secure Policy Manager 7.x, 8.00 before hotfix 2, 8.1x before hotfix 3 on Windows and hotfix 2 on Linux, and 9.00 before hotfix 4 on Windows and hotfix 2 on Linux, allows remote attackers to obtain sensitive information via a request to an invalid report, which reveals the installation path in an error message, as demonstrated with requests to (1) report/infection-table.html or (2) report/productsummary-table.html.

    Published: 25 Feb 2011
    7.2
    High

    CVE-2011-0037

    Last Modified: 11 Apr 2025

    Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key.

    Published: 25 Feb 2011
    9.3
    Critical

    CVE-2011-0926

    Last Modified: 11 Apr 2025

    A certain ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) does not properly verify the signature of an unspecified downloaded program, which allows remote attackers to execute arbitrary code by spoofing the CSD installation process, a different vulnerability than CVE-2010-0589.

    Published: 25 Feb 2011
    8.8
    High

    CVE-2011-1036

    Last Modified: 11 Apr 2025

    The XML Security Database Parser class in the XMLSecDB ActiveX control in the HIPSEngine component in the Management Server before 8.1.0.88, and the client before 1.6.450, in CA Host-Based Intrusion Prevention System (HIPS) 8.1, as used in CA Internet Security Suite (ISS) 2010, allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via vectors involving the SetXml and Save methods.

    Published: 25 Feb 2011
    6.5
    Medium

    CVE-2011-1100

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) findfid, (2) id, (3) selectfcat, (4) selectfmon, or (5) selectftag parameter in an images action.

    Published: 25 Feb 2011
    10
    Critical

    CVE-2011-0372

    Last Modified: 11 Apr 2025

    The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31640.

    Published: 25 Feb 2011
    9
    Critical

    CVE-2011-0374

    Last Modified: 11 Apr 2025

    The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31659.

    Published: 25 Feb 2011
    9
    Critical

    CVE-2011-0375

    Last Modified: 11 Apr 2025

    The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCth24671.

    Published: 25 Feb 2011
    10
    Critical

    CVE-2011-0376

    Last Modified: 11 Apr 2025

    The TFTP implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x, 1.6.0, and 1.6.1 allows remote attackers to obtain sensitive information via a GET request, aka Bug ID CSCte43876.

    Published: 25 Feb 2011
    8.3
    High

    CVE-2011-0378

    Last Modified: 11 Apr 2025

    The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587.

    Published: 25 Feb 2011
    7.5
    High

    CVE-2011-0380

    Last Modified: 11 Apr 2025

    Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP request, aka Bug ID CSCtc59562.

    Published: 25 Feb 2011
    10
    Critical

    CVE-2011-0381

    Last Modified: 11 Apr 2025

    Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a crafted request to the Java RMI interface, related to a "command injection vulnerability," aka Bug ID CSCtf97085.

    Published: 25 Feb 2011
    10
    Critical

    CVE-2011-0384

    Last Modified: 11 Apr 2025

    The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug ID CSCtf01253.

    Published: 25 Feb 2011
    7.8
    High

    CVE-2011-0389

    Last Modified: 11 Apr 2025

    Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allow remote attackers to cause a denial of service (process crash) via a crafted Real-Time Transport Control Protocol (RTCP) UDP packet, aka Bug ID CSCth60993.

    Published: 25 Feb 2011
    7.8
    High

    CVE-2011-0390

    Last Modified: 11 Apr 2025

    The XML-RPC implementation on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, 1.6.x, and 1.7.0 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka Bug ID CSCtj44534.

    Published: 25 Feb 2011
    7.8
    High

    CVE-2011-0391

    Last Modified: 11 Apr 2025

    Cisco TelePresence Recording Server devices with software 1.6.x allow remote attackers to cause a denial of service (thread consumption and device outage) via a malformed request, related to an "ad hoc recording" issue, aka Bug ID CSCtf97205.

    Published: 25 Feb 2011
    7.5
    High

    CVE-2011-0392

    Last Modified: 11 Apr 2025

    Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers to perform unspecified actions via a session on TCP port 8080, aka Bug ID CSCtg35833.

    Published: 25 Feb 2011
    7.8
    High

    CVE-2011-0395

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.20), 8.1 before 8.1(2.48), 8.2 before 8.2(3), and 8.3 before 8.3(2.1), when the RIP protocol and the Cisco Phone Proxy functionality are configured, allow remote attackers to cause a denial of service (device reload) via a RIP update, aka Bug ID CSCtg66583.

    Published: 25 Feb 2011
    7.8
    High

    CVE-2011-0377

    Last Modified: 11 Apr 2025

    Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allow remote attackers to cause a denial of service (service crash) via a malformed SOAP request in conjunction with a spoofed TelePresence Manager that supplies an invalid IP address, aka Bug ID CSCth03605.

    Published: 25 Feb 2011
    7.9
    High

    CVE-2011-0379

    Last Modified: 11 Apr 2025

    Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 1.6.x; Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x; Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x; and Cisco TelePresence Manager 1.2.x, 1.3.x, 1.4.x, 1.5.x, and 1.6.2 allows remote attackers to execute arbitrary code via a crafted Cisco Discovery Protocol packet, aka Bug IDs CSCtd75769, CSCtd75766, CSCtd75754, and CSCtd75761.

    Published: 25 Feb 2011
    10
    Critical

    CVE-2011-0382

    Last Modified: 11 Apr 2025

    The CGI subsystem on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 allows remote attackers to execute arbitrary commands via a request to TCP port 443, related to a "command injection vulnerability," aka Bug ID CSCtf97221.

    Published: 25 Feb 2011
    10
    Critical

    CVE-2011-0383

    Last Modified: 11 Apr 2025

    The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug IDs CSCtf42005 and CSCtf42008.

    Published: 25 Feb 2011
    10
    Critical

    CVE-2011-0385

    Last Modified: 11 Apr 2025

    The administrative web interface on Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote attackers to create or overwrite arbitrary files, and possibly execute arbitrary code, via a crafted request, aka Bug IDs CSCth85786 and CSCth61065.

    Published: 25 Feb 2011
    7.8
    High

    CVE-2011-0388

    Last Modified: 11 Apr 2025

    Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x do not properly restrict remote access to the Java servlet RMI interface, which allows remote attackers to cause a denial of service (memory consumption and web outage) via multiple crafted requests, aka Bug IDs CSCtg35830 and CSCtg35825.

    Published: 25 Feb 2011
    7.8
    High

    CVE-2011-0394

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.11), 7.1 and 7.2 before 7.2(5.1), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), 8.2 before 8.2(2.19), and 8.3 before 8.3(1.8); Cisco PIX Security Appliances 500 series devices; and Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(20), 3.2 before 3.2(20), 4.0 before 4.0(15), and 4.1 before 4.1(5) allow remote attackers to cause a denial of service (device reload) via a malformed Skinny Client Control Protocol (SCCP) message, aka Bug IDs CSCtg69457 and CSCtl84952.

    Published: 25 Feb 2011
    7.8
    High

    CVE-2011-0396

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 before 8.3(2.13), when a Certificate Authority (CA) is configured, allow remote attackers to read arbitrary files via unspecified vectors, aka Bug ID CSCtk12352.

    Published: 25 Feb 2011
    9
    Critical

    CVE-2011-0373

    Last Modified: 11 Apr 2025

    The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31685.

    Published: 25 Feb 2011
    9.3
    Critical

    CVE-2011-0386

    Last Modified: 11 Apr 2025

    The XML-RPC implementation on Cisco TelePresence Recording Server devices with software 1.6.x and 1.7.x before 1.7.1 allows remote attackers to overwrite files and consequently execute arbitrary code via a malformed request, aka Bug ID CSCti50739.

    Published: 25 Feb 2011
    8
    High

    CVE-2011-0387

    Last Modified: 11 Apr 2025

    The administrative web interface on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote authenticated users to cause a denial of service or have unspecified other impact via vectors involving access to a servlet, aka Bug ID CSCtf97164.

    Published: 25 Feb 2011
    7.8
    High

    CVE-2011-0393

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.12), 7.1 and 7.2 before 7.2(5.2), 8.0 before 8.0(5.21), 8.1 before 8.1(2.49), 8.2 before 8.2(3.6), and 8.3 before 8.3(2.7) and Cisco PIX Security Appliances 500 series devices, when transparent firewall mode is configured but IPv6 is not configured, allow remote attackers to cause a denial of service (packet buffer exhaustion and device outage) via IPv6 traffic, aka Bug ID CSCtj04707.

    Published: 25 Feb 2011
    4.9
    Medium

    CVE-2011-1083

    Last Modified: 11 Apr 2025

    The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.

    Published: 25 Feb 2011
    5.5
    Medium

    CVE-2011-1488

    Last Modified: 21 Nov 2024

    A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service via a sequence of repeated log messages sent within short periods of time.

    Published: 25 Feb 2011
    5.5
    Medium

    CVE-2011-1490

    Last Modified: 21 Nov 2024

    A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset

    Published: 25 Feb 2011
    5.5
    Medium

    CVE-2011-1489

    Last Modified: 21 Nov 2024

    A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset.

    Published: 25 Feb 2011
    6.2
    Medium

    CVE-2011-0452

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in the script function in Lunascape before 6.4.3 allows local users to gain privileges via a Trojan horse executable file in the current working directory.

    Published: 24 Feb 2011
    Unknown

    CVE-2007-1783

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-1685. Reason: This candidate is a duplicate of CVE-2007-1685. Notes: All CVE users should reference CVE-2007-1685 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Feb 2011
    4.3
    Medium

    CVE-2011-1469

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Streams component in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) by accessing an ftp:// URL during use of an HTTP proxy with the FTP wrapper.

    Published: 24 Feb 2011
    1.9
    Low

    CVE-2011-1019

    Last Modified: 11 Apr 2025

    The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.

    Published: 24 Feb 2011
    2.6
    Low

    CVE-2011-1068

    Last Modified: 11 Apr 2025

    Microsoft Windows Azure Software Development Kit (SDK) 1.3.x before 1.3.20121.1237, when Full IIS and a Web Role are used with an ASP.NET application, does not properly support the use of cookies for maintaining state, which allows remote attackers to obtain potentially sensitive information by reading an encrypted cookie and performing unspecified other steps.

    Published: 23 Feb 2011
    4.9
    Medium

    CVE-2011-0725

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in the org.debian.apt.UpdateCachePartially method in worker.py in Aptdaemon 0.40 in Ubuntu 10.10 and 11.04 allows local users to read arbitrary files via a full pathname in the sources_list argument, related to the D-Bus interface.

    Published: 23 Feb 2011
    6.8
    Medium

    CVE-2011-1003

    Last Modified: 11 Apr 2025

    Double free vulnerability in the vba_read_project_strings function in vba_extract.c in libclamav in ClamAV before 0.97 might allow remote attackers to execute arbitrary code via crafted Visual Basic for Applications (VBA) data in a Microsoft Office document. NOTE: some of these details are obtained from third party information.

    Published: 23 Feb 2011
    5.8
    Medium

    CVE-2011-0717

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in Red Hat Network (RHN) Satellite Server 5.4 allows remote attackers to hijack web sessions via unspecified vectors related to Spacewalk.

    Published: 23 Feb 2011
    5.8
    Medium

    CVE-2011-0718

    Last Modified: 11 Apr 2025

    Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to conduct brute force password guessing attacks.

    Published: 23 Feb 2011
    4.3
    Medium

    CVE-2011-1063

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cherry-Design Photopad 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) data[title] parameters in an edit action to files.php, or (3) id parameter in a view action to gallery.php.

    Published: 22 Feb 2011
    9.3
    Critical

    CVE-2011-1065

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the PIPIWebPlayer ActiveX control (PIWebPlayer.ocx) in PIPI Player 2.8.0.0 allow remote attackers to execute arbitrary code via long arguments to the (1) PlayURL or (2) PlayURLWithLocalPlayer methods.

    Published: 22 Feb 2011
    2.6
    Low

    CVE-2011-1066

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Messaging module 6.x-2.x before 6.x-2.4 and 6.x-4.x before 6.x-4.0-beta8 for Drupal allows remote attackers with administer messaging permissions to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Feb 2011
    7.5
    High

    CVE-2011-1061

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in memberlist.php in WSN Guest 1.24 allows remote attackers to execute arbitrary SQL commands via the time parameter.

    Published: 22 Feb 2011