CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2011-0587

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-0604.

    Published: 8 Feb 2011
    9.3
    Critical

    CVE-2011-0589

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0563 and CVE-2011-0606.

    Published: 8 Feb 2011
    9.3
    Critical

    CVE-2011-0590

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a 3D file, a different vulnerability than CVE-2011-0591, CVE-2011-0592, CVE-2011-0593, CVE-2011-0595, and CVE-2011-0600.

    Published: 8 Feb 2011
    9.3
    Critical

    CVE-2011-0591

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a crafted Universal 3D (U3D) file that triggers a buffer overflow during decompression, related to Texture and rgba, a different vulnerability than CVE-2011-0590, CVE-2011-0592, CVE-2011-0593, CVE-2011-0595, and CVE-2011-0600.

    Published: 8 Feb 2011
    9.3
    Critical

    CVE-2011-0603

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image, a different vulnerability than CVE-2011-0566 and CVE-2011-0567.

    Published: 8 Feb 2011
    9.3
    Critical

    CVE-2011-0606

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in rt3d.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors related to a crafted length value, a different vulnerability than CVE-2011-0563 and CVE-2011-0589.

    Published: 8 Feb 2011
    5
    Medium

    CVE-2010-4022

    Last Modified: 11 Apr 2025

    The do_standalone function in the MIT krb5 KDC database propagation daemon (kpropd) in Kerberos 1.7, 1.8, and 1.9, when running in standalone mode, does not properly handle when a worker child process "exits abnormally," which allows remote attackers to cause a denial of service (listening process termination, no new connections, and lack of updates in slave KVC) via unspecified vectors.

    Published: 8 Feb 2011
    9.3
    Critical

    CVE-2011-0559

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted parameters to an unspecified ActionScript method that cause a parameter to be used as an object pointer, a different vulnerability than CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0578, CVE-2011-0607, and CVE-2011-0608.

    Published: 8 Feb 2011
    9.3
    Critical

    CVE-2011-0566

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image, a different vulnerability than CVE-2011-0567 and CVE-2011-0603.

    Published: 8 Feb 2011
    9.3
    Critical

    CVE-2011-0573

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0574, CVE-2011-0578, CVE-2011-0607, and CVE-2011-0608.

    Published: 8 Feb 2011
    9.3
    Critical

    CVE-2011-0593

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a crafted Universal 3D (U3D) file that triggers a buffer overflow during decompression, a different vulnerability than CVE-2011-0590, CVE-2011-0591, CVE-2011-0592, CVE-2011-0595, and CVE-2011-0600.

    Published: 8 Feb 2011
    9.3
    Critical

    CVE-2011-0595

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a crafted Universal 3D (U3D) file that triggers a buffer overflow during decompression, a different vulnerability than CVE-2011-0590, CVE-2011-0591, CVE-2011-0592, CVE-2011-0593, and CVE-2011-0600.

    Published: 8 Feb 2011
    9.3
    Critical

    CVE-2011-0602

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via crafted JP2K record types in a JPEG2000 image in a PDF file, which causes heap corruption, a different vulnerability than CVE-2011-0596, CVE-2011-0598, and CVE-2011-0599.

    Published: 8 Feb 2011
    5
    Medium

    CVE-2011-0899

    Last Modified: 11 Apr 2025

    The AES encryption module 7.x-1.4 for Drupal leaves certain debugging code enabled in release, which records the plaintext password of the last logged-in user and allows remote attackers to gain privileges as that user.

    Published: 7 Feb 2011
    9.3
    Critical

    CVE-2011-0324

    Last Modified: 11 Apr 2025

    Multiple heap-based buffer overflows in Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allow remote attackers to execute arbitrary code via a long (1) KeyString property, (2) NewPath parameter to the SetLocalIniFilePath method, or (3) NewPortPath parameter to the SetTabletPortPath method.

    Published: 7 Feb 2011
    9.3
    Critical

    CVE-2011-0531

    Last Modified: 11 Apr 2025

    demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska) file that triggers memory corruption, related to "class mismatching" and the MKV_IS_ID macro.

    Published: 7 Feb 2011
    6.8
    Medium

    CVE-2011-0903

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitrary files and possibly have other unspecified impact via a .. (dot dot) in the (1) awcm_theme or (2) awcm_lang cookie to (a) index.php or (b) header.php.

    Published: 7 Feb 2011
    6.2
    Medium

    CVE-2010-4506

    Last Modified: 11 Apr 2025

    Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is reachable from the "Certificate Export" wizard.

    Published: 7 Feb 2011
    9.3
    Critical

    CVE-2011-0323

    Last Modified: 11 Apr 2025

    Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary content.

    Published: 7 Feb 2011
    6.8
    Medium

    CVE-2011-0522

    Last Modified: 11 Apr 2025

    The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/codec/subtitles/subsusf.c) in VideoLAN VLC Media Player 1.1 before 1.1.6-rc allows remote attackers to execute arbitrary code via a subtitle with an opening "<" without a closing ">" in an MKV file, which triggers heap memory corruption, as demonstrated using refined-australia-blu720p-sample.mkv.

    Published: 7 Feb 2011
    6.9
    Medium

    CVE-2011-0902

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in the Java Service in Sun Microsystems SunScreen Firewall on SunOS 5.9 allow local users to execute arbitrary code via a modified (1) PATH or (2) LD_LIBRARY_PATH environment variable.

    Published: 7 Feb 2011
    4.6
    Medium

    CVE-2011-1020

    Last Modified: 11 Apr 2025

    The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.

    Published: 7 Feb 2011
    4.9
    Medium

    CVE-2011-1082

    Last Modified: 11 Apr 2025

    fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.

    Published: 5 Feb 2011
    1.2
    Low

    CVE-2010-3718

    Last Modified: 11 Apr 2025

    Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

    Published: 5 Feb 2011
    7.5
    High

    CVE-2011-0781

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.84 does not properly handle autofill profile merging, which has unspecified impact and remote attack vectors.

    Published: 4 Feb 2011
    5
    Medium

    CVE-2011-0776

    Last Modified: 11 Apr 2025

    The sandbox implementation in Google Chrome before 9.0.597.84 on Mac OS X might allow remote attackers to obtain potentially sensitive information about local files via vectors related to the stat system call.

    Published: 4 Feb 2011
    7.5
    High

    CVE-2011-0777

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 9.0.597.84 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to image loading.

    Published: 4 Feb 2011
    5
    Medium

    CVE-2011-0782

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.84 on Mac OS X does not properly mitigate an unspecified flaw in the Mac OS X 10.5 SSL libraries, which allows remote attackers to cause a denial of service (application crash) via unknown vectors.

    Published: 4 Feb 2011
    4.3
    Medium

    CVE-2011-0783

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 9.0.597.84 allows user-assisted remote attackers to cause a denial of service (application crash) via vectors involving a "bad volume setting."

    Published: 4 Feb 2011
    6.8
    Medium

    CVE-2011-0784

    Last Modified: 11 Apr 2025

    Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code via vectors related to audio.

    Published: 4 Feb 2011
    5
    Medium

    CVE-2011-0779

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.84 does not properly handle a missing key in an extension, which allows remote attackers to cause a denial of service (application crash) via a crafted extension.

    Published: 4 Feb 2011
    6.8
    Medium

    CVE-2011-0780

    Last Modified: 11 Apr 2025

    The PDF event handler in Google Chrome before 9.0.597.84 does not properly interact with print operations, which allows user-assisted remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.

    Published: 4 Feb 2011
    7.5
    High

    CVE-2011-0539

    Last Modified: 29 May 2026

    The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks.

    Published: 4 Feb 2011
    5
    Medium

    CVE-2011-0049

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the help command, as demonstrated using (1) a crafted email and (2) cgi-bin/mj_wwwusr in the web interface.

    Published: 4 Feb 2011
    7.5
    High

    CVE-2011-0537

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in (1) languages/Language.php and (2) includes/StubObject.php in MediaWiki 1.8.0 and other versions before 1.16.2, when running on Windows and possibly Novell Netware, allow remote attackers to include and execute arbitrary local PHP files via vectors related to a crafted language file and the Language::factory function.

    Published: 4 Feb 2011
    4.3
    Medium

    CVE-2011-0772

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow remote attackers to inject arbitrary web script or HTML via the (1) color parameter to includes/blogroll.php or (2) src parameter to includes/timwrapper.php.

    Published: 4 Feb 2011
    4.3
    Medium

    CVE-2011-0773

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the image parameter.

    Published: 4 Feb 2011
    5
    Medium

    CVE-2011-0775

    Last Modified: 11 Apr 2025

    pivotx/modules/module_image.php in PivotX 2.2.2 allows remote attackers to obtain sensitive information via a non-existent file in the image parameter, which reveals the installation path in an error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Feb 2011
    4.3
    Medium

    CVE-2011-0047

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."

    Published: 4 Feb 2011
    6.8
    Medium

    CVE-2011-0771

    Last Modified: 11 Apr 2025

    The Janrain Engage (formerly RPX) module 6.x-1.3 for Drupal does not validate the file for a profile image, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks and possibly execute arbitrary PHP code by causing a crafted avatar to be downloaded from an external login provider site.

    Published: 4 Feb 2011
    7.2
    High

    CVE-2011-0649

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2.1 through 8.3.0, Enterprise Message Service (EMS) 5.1.0 through 6.0.0, Runtime Agent (TRA) 5.6.2 through 5.7.0, Silver BPM Service before 1.0.4, Silver CAP Service vebefore 1.0.2, and Silver BusinessWorks Service 1.0.0, when running on Unix systems, allow local users to gain root privileges via unknown vectors related to SUID and (1) Rendezvous Routing Daemon (rvrd), (2) Rendezvous Secure Daemon (rvsd), (3) Rendezvous Secure Routing Daemon (rvsrd), and (4) EMS Server (tibemsd).

    Published: 4 Feb 2011
    5
    Medium

    CVE-2011-0774

    Last Modified: 11 Apr 2025

    PivotX before 2.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) includes/ping.php and (2) includes/spamping.php, which reveals the installation path in an error message.

    Published: 4 Feb 2011
    10
    Critical

    CVE-2009-5052

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.

    Published: 3 Feb 2011
    7.5
    High

    CVE-2009-5053

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a cache file.

    Published: 3 Feb 2011
    7.5
    High

    CVE-2009-5054

    Last Modified: 11 Apr 2025

    Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.

    Published: 3 Feb 2011
    10
    Critical

    CVE-2010-4724

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.

    Published: 3 Feb 2011
    10
    Critical

    CVE-2010-4725

    Last Modified: 11 Apr 2025

    Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and remote attack vectors.

    Published: 3 Feb 2011
    10
    Critical

    CVE-2010-4726

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors. NOTE: this might overlap CVE-2009-1669.

    Published: 3 Feb 2011
    10
    Critical

    CVE-2010-4727

    Last Modified: 11 Apr 2025

    Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.

    Published: 3 Feb 2011
    9.3
    Critical

    CVE-2010-4723

    Last Modified: 11 Apr 2025

    Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which has unspecified impact and remote attack vectors.

    Published: 3 Feb 2011