CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2011-0517

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted 0x02 opcode to TCP port 46823.

    Published: 20 Jan 2011
    5.1
    Medium

    CVE-2011-0518

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via the system parameter to index.php.

    Published: 20 Jan 2011
    7.5
    High

    CVE-2011-0519

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in gallery.php in Gallarific PHP Photo Gallery script 2.1 and possibly other versions allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 20 Jan 2011
    6.8
    Medium

    CVE-2010-3928

    Last Modified: 11 Apr 2025

    Ruby Version Manager (RVM) before 1.2.1 writes file contents to a terminal without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via a crafted file, related to an "escape sequence injection vulnerability." NOTE: some of these details are obtained from third party information.

    Published: 20 Jan 2011
    4.3
    Medium

    CVE-2010-3931

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM bbs 1.07 and earlier, PM up bbs 1.08 and earlier, and PM forum 1.18 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 20 Jan 2011
    6.2
    Medium

    CVE-2010-4338

    Last Modified: 11 Apr 2025

    ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cuneiform is invoked as the OCR engine.

    Published: 20 Jan 2011
    6
    Medium

    CVE-2011-0495

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows remote authenticated users to execute arbitrary code via crafted caller ID data in vectors involving the (1) SIP channel driver, (2) URIENCODE dialplan function, or (3) AGI dialplan function.

    Published: 20 Jan 2011
    7.8
    High

    CVE-2011-0497

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to read arbitrary files via "../\" (dot dot forward-slash backslash) sequences in a crafted request.

    Published: 20 Jan 2011
    9.3
    Critical

    CVE-2011-0499

    Last Modified: 11 Apr 2025

    Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earlier versions, and VideoSpirit Lite 1.4.0.1 and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a VideoSpirit project (.visprj) file containing a valitem element with a long "name" attribute. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Jan 2011
    4.3
    Medium

    CVE-2011-0508

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header, which is stored by system/libraries/Environment.php but not properly handled by a comments action to main.php.

    Published: 20 Jan 2011
    2.1
    Low

    CVE-2011-0515

    Last Modified: 11 Apr 2025

    KisKrnl.sys 2011.1.13.89 and earlier in Kingsoft AntiVirus 2011 SP5.2 allows local users to cause a denial of service (crash) via a crafted request that is not properly handled by the KiFastCallEntry hook.

    Published: 20 Jan 2011
    7.5
    High

    CVE-2011-0516

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in mainx_a.php in E-PROMPT C BetMore Site Suite 4.0 through 4.2.0 allows remote attackers to execute arbitrary SQL commands via the bid parameter.

    Published: 20 Jan 2011
    7.6
    High

    CVE-2010-4701

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers to execute arbitrary code via a long record in a Fax Cover Page (.cov) file. NOTE: some of these details are obtained from third party information.

    Published: 20 Jan 2011
    10
    Critical

    CVE-2011-0496

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a "design vulnerability."

    Published: 20 Jan 2011
    4.3
    Medium

    CVE-2011-0507

    Last Modified: 11 Apr 2025

    FTPService.exe in Blackmoon FTP 3.1 Build 1735 and Build 1736 (3.1.7.1736), and possibly other versions before 3.1.8.1737, allows remote attackers to cause a denial of service (crash) via a large number of PORT commands with long arguments, which triggers a NULL pointer dereference. NOTE: some of these details are obtained from third party information.

    Published: 20 Jan 2011
    3.5
    Low

    CVE-2011-0311

    Last Modified: 11 Apr 2025

    The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote authenticated users to cause a denial of service (JVM segmentation fault, and possibly memory consumption or an infinite loop) via a crafted attribute length field in a class file, which triggers a buffer over-read.

    Published: 20 Jan 2011
    3.5
    Low

    CVE-2010-4429

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Agile Core component in Oracle Supply Chain Products Suite 9.3.0.2 and 9.3.1 allows remote authenticated users to affect integrity via unknown vectors related to Web Client, a different vulnerability than CVE-2010-3505.

    Published: 19 Jan 2011
    4
    Medium

    CVE-2010-4430

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 9.1 Update 2010-F allows remote authenticated users to affect confidentiality via unknown vectors related to Absence Management.

    Published: 19 Jan 2011
    1
    Low

    CVE-2010-4431

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Java System Portal Server 7.1 and 7.2 allows local users to affect confidentiality via unknown vectors related to Proxy.

    Published: 19 Jan 2011
    4
    Medium

    CVE-2010-4434

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.50.0 through 8.50.14 and 8.51.0 through 8.51.04 allows remote authenticated users to affect confidentiality via unknown vectors related to Portal.

    Published: 19 Jan 2011
    10
    Critical

    CVE-2010-4435

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to CDE Calendar Manager Service Daemon and RPC. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from other software vendors that this affects other operating systems, such as HP-UX, or claims from a reliable third party that this is a buffer overflow in rpc.cmsd via long XDR-encoded ASCII strings in RPC call 10.

    Published: 19 Jan 2011
    5
    Medium

    CVE-2010-4436

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Management Center (SunMC) 4.0 allows remote attackers to affect confidentiality via unknown vectors related to Web Console.

    Published: 19 Jan 2011
    5.8
    Medium

    CVE-2010-4437

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet Container.

    Published: 19 Jan 2011
    5.7
    Medium

    CVE-2010-4438

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle GlassFish 2.1, 2.1.1, and 3.0.1, and Java System Message Queue 4.1 allows local users to affect confidentiality, integrity, and availability, related to Java Message Service (JMS).

    Published: 19 Jan 2011
    4
    Medium

    CVE-2010-4439

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 9.0 Bundle #14 and 9.1 Bundle #4 allows remote authenticated users to affect confidentiality via unknown vectors related to eProfile - Manager Desktop.

    Published: 19 Jan 2011
    6.8
    Medium

    CVE-2010-4444

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Java System Access Manager and Oracle OpenSSO 7, 7.1, and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 19 Jan 2011
    4.6
    Medium

    CVE-2010-4446

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability via unknown vectors related to RDS and Kernel/InfiniBand.

    Published: 19 Jan 2011
    3.5
    Low

    CVE-2010-4432

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Manager component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Infrastructure.

    Published: 19 Jan 2011
    5
    Medium

    CVE-2010-4433

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality via unknown vectors related to Ethernet and the Driver sub-component.

    Published: 19 Jan 2011
    4.4
    Medium

    CVE-2010-4442

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability via unknown vectors related to the Kernel.

    Published: 19 Jan 2011
    4.4
    Medium

    CVE-2010-4443

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability, related to Kernel/NFS.

    Published: 19 Jan 2011
    4
    Medium

    CVE-2010-4445

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 9.0 Bundle #14 and 9.1 Bundle #4 allows remote authenticated users to affect confidentiality via unknown vectors related to Talent Acquisition Manager.

    Published: 19 Jan 2011
    10
    Critical

    CVE-2010-4449

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Audit Vault component in Oracle Audit Vault 10.2.3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that this issue is related to a crafted parameter in an action.execute request to the av component on TCP port 5700.

    Published: 19 Jan 2011
    4.3
    Medium

    CVE-2010-4453

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 7.0.7, 8.1.6, 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect integrity via unknown vectors related to Servlet Container.

    Published: 19 Jan 2011
    4.3
    Medium

    CVE-2010-4456

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Java System Communications Express 6.2 and 6.3 allows remote attackers to affect integrity via unknown vectors related to Web Mail.

    Published: 19 Jan 2011
    7.8
    High

    CVE-2010-4457

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availability, related to SMB and CIFS.

    Published: 19 Jan 2011
    4.1
    Medium

    CVE-2010-4458

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability, related to ZFS.

    Published: 19 Jan 2011
    5.5
    Medium

    CVE-2010-4461

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 8.9 Bundle #23, 9.0 Bundle #14, and 9.1 Bundle #4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to ePerformance.

    Published: 19 Jan 2011
    4.6
    Medium

    CVE-2010-4459

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability via unknown vectors related to SCTP and Kernel/sockfs.

    Published: 19 Jan 2011
    3.6
    Low

    CVE-2010-4460

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality and integrity via unknown vectors related to Fault Manager Daemon.

    Published: 19 Jan 2011
    4.4
    Medium

    CVE-2010-4440

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle 10 and 11 Express allows local users to affect availability via unknown vectors related to the Kernel.

    Published: 19 Jan 2011
    5.5
    Medium

    CVE-2010-4441

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 9.1 Bundle #4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Manager.

    Published: 19 Jan 2011
    6.4
    Medium

    CVE-2010-4455

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.2 and 11.1.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Apache Plugin.

    Published: 19 Jan 2011
    6.4
    Medium

    CVE-2010-4464

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Convergence 1.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Webmail.

    Published: 19 Jan 2011
    3.5
    Low

    CVE-2010-3505

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Agile Core component in Oracle Supply Chain Products Suite 9.3.0.2 and 9.3.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Folders, Files & Attachments, a different vulnerability than CVE-2010-4429.

    Published: 19 Jan 2011
    3.6
    Low

    CVE-2010-3586

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 9 allows local users to affect confidentiality and integrity via unknown vectors related to XScreenSaver.

    Published: 19 Jan 2011
    5.5
    Medium

    CVE-2010-3588

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 10.1.2.3, 11.1.1.2.0, and 11.1.1.3.0 allows remote authenticated users to affect confidentiality and integrity, related to EUL Code & Schema.

    Published: 19 Jan 2011
    4
    Medium

    CVE-2010-3589

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle Applications 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Logout.

    Published: 19 Jan 2011
    4.9
    Medium

    CVE-2010-3590

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Spatial component in Oracle Database Server 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality and integrity, related to MDSYS.

    Published: 19 Jan 2011
    8.5
    High

    CVE-2010-3592

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity and availability via unknown vectors related to Internal Operations.

    Published: 19 Jan 2011