CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2010-4468

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, and 5.0 Update 27 and earlier, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity via unknown vectors related to JDBC.

    Published: 15 Feb 2011
    5
    Medium

    CVE-2010-4471

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, and 5.0 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to 2D. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is related to the exposure of system properties via vectors related to Font.createFont and exception text.

    Published: 15 Feb 2011
    2.6
    Low

    CVE-2010-4472

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect availability, related to XML Digital Signature and unspecified APIs. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue involves the replacement of the "XML DSig Transform or C14N algorithm implementations."

    Published: 15 Feb 2011
    10
    Critical

    CVE-2010-4473

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound and unspecified APIs, a different vulnerability than CVE-2010-4454 and CVE-2010-4462.

    Published: 15 Feb 2011
    5.9
    Medium

    CVE-2011-0704

    Last Modified: 21 Nov 2024

    389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modify request.

    Published: 15 Feb 2011
    4.3
    Medium

    CVE-2008-7274

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not providing a password or (2) providing an empty password.

    Published: 14 Feb 2011
    10
    Critical

    CVE-2010-4733

    Last Modified: 11 Apr 2025

    WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms have a default username and password, which makes it easier for remote attackers to obtain superadmin access via the web interface, a different vulnerability than CVE-2009-4463.

    Published: 14 Feb 2011
    9.3
    Critical

    CVE-2011-1033

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote attackers to execute arbitrary code via crafted arguments in the USELASTCOMMITTED session environment option in a SQL SET ENVIRONMENT statement.

    Published: 14 Feb 2011
    6.8
    Medium

    CVE-2010-4730

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the page parameter, a different vulnerability than CVE-2009-4463.

    Published: 14 Feb 2011
    6.8
    Medium

    CVE-2010-4731

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to read arbitrary files via a full pathname in the file parameter, a different vulnerability than CVE-2009-4463.

    Published: 14 Feb 2011
    9
    Critical

    CVE-2010-4732

    Last Modified: 11 Apr 2025

    cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to execute arbitrary code by using a config.html 2.conf action to replace the logo page's GIF image file with a file containing this code, a different vulnerability than CVE-2009-4463.

    Published: 14 Feb 2011
    6.8
    Medium

    CVE-2011-1032

    Last Modified: 11 Apr 2025

    IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, which has unspecified impact and attack vectors.

    Published: 14 Feb 2011
    5
    Medium

    CVE-2011-0986

    Last Modified: 11 Apr 2025

    phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE files, which allows remote attackers to obtain the installation path via a direct request for a nonexistent file.

    Published: 14 Feb 2011
    6.5
    Medium

    CVE-2011-0987

    Last Modified: 11 Apr 2025

    The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.

    Published: 14 Feb 2011
    3.5
    Low

    CVE-2011-1029

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report.

    Published: 14 Feb 2011
    3.3
    Low

    CVE-2011-1031

    Last Modified: 11 Apr 2025

    The feh_unique_filename function in utils.c in feh 1.11.2 and earlier might allow local users to create arbitrary files via a symlink attack on a /tmp/feh_ temporary file, a different vulnerability than CVE-2011-0702.

    Published: 14 Feb 2011
    4.3
    Medium

    CVE-2011-1030

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Wikis component in IBM Lotus Connections 3.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Confirm New Page scene."

    Published: 14 Feb 2011
    3.3
    Low

    CVE-2011-0702

    Last Modified: 11 Apr 2025

    The feh_unique_filename function in utils.c in feh before 1.11.2 might allow local users to overwrite arbitrary files via a symlink attack on a /tmp/feh_ temporary file.

    Published: 14 Feb 2011
    6.8
    Medium

    CVE-2011-0447

    Last Modified: 11 Apr 2025

    Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged (1) AJAX or (2) API requests that leverage "combinations of browser plugins and HTTP redirects," a related issue to CVE-2011-0696.

    Published: 14 Feb 2011
    6.8
    Medium

    CVE-2011-0696

    Last Modified: 11 Apr 2025

    Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged AJAX requests that leverage a "combination of browser plugins and redirects," a related issue to CVE-2011-0447.

    Published: 14 Feb 2011
    4.3
    Medium

    CVE-2011-0697

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 might allow remote attackers to inject arbitrary web script or HTML via a filename associated with a file upload.

    Published: 14 Feb 2011
    7.5
    High

    CVE-2011-0698

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 on Windows might allow remote attackers to read or execute files via a / (slash) character in a key in a session cookie, related to session replays.

    Published: 14 Feb 2011
    4.3
    Medium

    CVE-2011-0446

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the mail_to helper in Ruby on Rails before 2.3.11, and 3.x before 3.0.4, when javascript encoding is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) name or (2) email value.

    Published: 14 Feb 2011
    4.3
    Medium

    CVE-2011-0708

    Last Modified: 11 Apr 2025

    exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) via an image with a crafted Image File Directory (IFD) that triggers a buffer over-read.

    Published: 14 Feb 2011
    1.9
    Low

    CVE-2011-1016

    Last Modified: 11 Apr 2025

    The Radeon GPU drivers in the Linux kernel before 2.6.38-rc5 do not properly validate data related to the AA resolve registers, which allows local users to write to arbitrary memory locations associated with (1) Video RAM (aka VRAM) or (2) the Graphics Translation Table (GTT) via crafted values.

    Published: 14 Feb 2011
    5.4
    Medium

    CVE-2011-1079

    Last Modified: 11 Apr 2025

    The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.

    Published: 14 Feb 2011
    2.1
    Low

    CVE-2011-1080

    Last Modified: 11 Apr 2025

    The do_replace function in net/bridge/netfilter/ebtables.c in the Linux kernel before 2.6.39 does not ensure that a certain name field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability to replace a table, and then reading a modprobe command line.

    Published: 14 Feb 2011
    1.9
    Low

    CVE-2011-1078

    Last Modified: 11 Apr 2025

    The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via the SCO_CONNINFO option.

    Published: 14 Feb 2011
    7.2
    High

    CVE-2011-0712

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the caiaq Native Instruments USB audio functionality in the Linux kernel before 2.6.38-rc4-next-20110215 might allow attackers to cause a denial of service or possibly have unspecified other impact via a long USB device name, related to (1) the snd_usb_caiaq_audio_init function in sound/usb/caiaq/audio.c and (2) the snd_usb_caiaq_midi_init function in sound/usb/caiaq/midi.c.

    Published: 14 Feb 2011
    1.9
    Low

    CVE-2011-1098

    Last Modified: 11 Apr 2025

    Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.

    Published: 13 Feb 2011
    6.9
    Medium

    CVE-2011-1154

    Last Modified: 11 Apr 2025

    The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

    Published: 13 Feb 2011
    1.9
    Low

    CVE-2011-1155

    Last Modified: 11 Apr 2025

    The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

    Published: 13 Feb 2011
    9.3
    Critical

    CVE-2011-0978

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via vectors related to an axis properties record, and improper incrementing of an array index, aka "Excel Array Indexing Vulnerability."

    Published: 10 Feb 2011
    9.3
    Critical

    CVE-2011-0979

    Last Modified: 11 Apr 2025

    Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; and Excel Viewer SP2 do not properly handle errors during the parsing of Office Art records in Excel spreadsheets, which allows remote attackers to execute arbitrary code via a malformed object record, related to a "stray reference," aka "Excel Linked List Corruption Vulnerability."

    Published: 10 Feb 2011
    9.3
    Critical

    CVE-2011-0980

    Last Modified: 11 Apr 2025

    Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability."

    Published: 10 Feb 2011
    10
    Critical

    CVE-2011-0982

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 9.0.597.94 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG font faces.

    Published: 10 Feb 2011
    7.5
    High

    CVE-2011-0985

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.94 does not properly perform process termination upon memory exhaustion, which has unspecified impact and remote attack vectors.

    Published: 10 Feb 2011
    9.3
    Critical

    CVE-2011-0977

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via malformed shape data in the Office drawing file format, aka "Microsoft Office Graphic Object Dereferencing Vulnerability."

    Published: 10 Feb 2011
    5
    Medium

    CVE-2011-0984

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.94 does not properly handle plug-ins, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 10 Feb 2011
    9.3
    Critical

    CVE-2011-0976

    Last Modified: 11 Apr 2025

    Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and PowerPoint Viewer 2007 SP2 do not properly handle Office Art containers that have invalid records, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PowerPoint document with a container that triggers certain access to an uninitialized object, aka "OfficeArt Atom RCE Vulnerability."

    Published: 10 Feb 2011
    7.5
    High

    CVE-2011-0981

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 10 Feb 2011
    7.5
    High

    CVE-2011-0983

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 10 Feb 2011
    5
    Medium

    CVE-2010-4327

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the NCP service in Novell eDirectory 8.8.5 before 8.8.5.6 and 8.8.6 before 8.8.6.2 allows remote attackers to cause a denial of service (hang) via a malformed FileSetLock request to port 524.

    Published: 10 Feb 2011
    9.3
    Critical

    CVE-2011-0564

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows use weak permissions for unspecified files, which allows attackers to gain privileges via unknown vectors.

    Published: 10 Feb 2011
    6.8
    Medium

    CVE-2011-0568

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Mac OS X allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.

    Published: 10 Feb 2011
    6.9
    Medium

    CVE-2011-0588

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2011-0562 and CVE-2011-0570.

    Published: 10 Feb 2011
    6.8
    Medium

    CVE-2011-0605

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 10 Feb 2011
    10
    Critical

    CVE-2011-0647

    Last Modified: 11 Apr 2025

    The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.

    Published: 10 Feb 2011
    10
    Critical

    CVE-2011-0758

    Last Modified: 11 Apr 2025

    The eCS component (ECSQdmn.exe) in CA ETrust Secure Content Manager 8.0 and CA Gateway Security 8.1 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted request to port 1882, involving an incorrect integer calculation and a heap-based buffer overflow.

    Published: 10 Feb 2011
    6.9
    Medium

    CVE-2011-0570

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2011-0562 and CVE-2011-0588.

    Published: 10 Feb 2011