CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-0115

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in login.php in the GUI management console in Symantec Web Gateway 4.5 before 4.5.0.376 allows remote attackers to execute arbitrary SQL commands via the USERNAME parameter.

    Published: 14 Jan 2011
    4.3
    Medium

    CVE-2010-4339

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Hypermail 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted From address, which is not properly handled when indexing messages.

    Published: 14 Jan 2011
    7.5
    High

    CVE-2010-4335

    Last Modified: 11 Apr 2025

    The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.

    Published: 14 Jan 2011
    9.3
    Critical

    CVE-2010-4566

    Last Modified: 11 Apr 2025

    The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in the password field.

    Published: 14 Jan 2011
    3.3
    Low

    CVE-2010-4337

    Last Modified: 11 Apr 2025

    The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnings.$$, or (3) /tmp/gnash-configure-recommended.$$ files.

    Published: 14 Jan 2011
    5
    Medium

    CVE-2011-0470

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle extensions notification, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 14 Jan 2011
    10
    Critical

    CVE-2011-0473

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with CANVAS elements, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 14 Jan 2011
    10
    Critical

    CVE-2011-0474

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 14 Jan 2011
    9.3
    Critical

    CVE-2011-0475

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a PDF document.

    Published: 14 Jan 2011
    10
    Critical

    CVE-2011-0476

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allow remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a PDF document that triggers an out-of-memory error.

    Published: 14 Jan 2011
    10
    Critical

    CVE-2011-0477

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle a mismatch in video frame sizes, which allows remote attackers to cause a denial of service (incorrect memory access) or possibly have unspecified other impact via unknown vectors.

    Published: 14 Jan 2011
    10
    Critical

    CVE-2011-0478

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle SVG use elements, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

    Published: 14 Jan 2011
    9.3
    Critical

    CVE-2011-0481

    Last Modified: 11 Apr 2025

    Buffer overflow in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to PDF shading.

    Published: 14 Jan 2011
    5
    Medium

    CVE-2011-0483

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of an unspecified variable during handling of video, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 14 Jan 2011
    7.5
    High

    CVE-2011-0484

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform DOM node removal, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale rendering node."

    Published: 14 Jan 2011
    10
    Critical

    CVE-2011-0485

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle speech data, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "stale pointer."

    Published: 14 Jan 2011
    10
    Critical

    CVE-2011-0471

    Last Modified: 11 Apr 2025

    The node-iteration implementation in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 does not properly handle pointers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 14 Jan 2011
    9.3
    Critical

    CVE-2011-0472

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle the printing of PDF documents, which allows user-assisted remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a multi-page document.

    Published: 14 Jan 2011
    9.3
    Critical

    CVE-2011-0480

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue.

    Published: 14 Jan 2011
    7.5
    High

    CVE-2011-0479

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly interact with extensions, which allows remote attackers to cause a denial of service via a crafted extension that triggers an uninitialized pointer.

    Published: 14 Jan 2011
    6.9
    Medium

    CVE-2011-0008

    Last Modified: 11 Apr 2025

    A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command. NOTE: this vulnerability exists because of a CVE-2009-0034 regression.

    Published: 14 Jan 2011
    7.5
    High

    CVE-2010-3924

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Aimluck Aipo before 5.1.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Jan 2011
    10
    Critical

    CVE-2011-0261

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in jovgraph.exe in jovgraph in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a malformed displayWidth option in the arg parameter.

    Published: 13 Jan 2011
    10
    Critical

    CVE-2011-0264

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in ovutil.dll in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long COOKIE variable.

    Published: 13 Jan 2011
    10
    Critical

    CVE-2011-0265

    Last Modified: 11 Apr 2025

    Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long data_select1 parameter.

    Published: 13 Jan 2011
    10
    Critical

    CVE-2011-0266

    Last Modified: 11 Apr 2025

    Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long nameParams parameter, a different vulnerability than CVE-2011-0267.2.

    Published: 13 Jan 2011
    10
    Critical

    CVE-2011-0267

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attackers to execute arbitrary code via a long (1) schdParams or (2) nameParams parameter, a different vulnerability than CVE-2011-0266.

    Published: 13 Jan 2011
    10
    Critical

    CVE-2011-0268

    Last Modified: 11 Apr 2025

    Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long text1 parameter.

    Published: 13 Jan 2011
    10
    Critical

    CVE-2011-0269

    Last Modified: 11 Apr 2025

    Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long schd_select1 parameter.

    Published: 13 Jan 2011
    10
    Critical

    CVE-2011-0270

    Last Modified: 11 Apr 2025

    Format string vulnerability in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via format string specifiers in input data that involves an invalid template name.

    Published: 13 Jan 2011
    6.8
    Medium

    CVE-2011-0310

    Last Modified: 11 Apr 2025

    Buffer overflow in IBM WebSphere MQ 7.0 before 7.0.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted header field in a message.

    Published: 13 Jan 2011
    10
    Critical

    CVE-2011-0263

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in ovas.exe in the OVAS service in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attackers to execute arbitrary code via a long (1) Source Node or (2) Destination Node variable.

    Published: 13 Jan 2011
    10
    Critical

    CVE-2011-0271

    Last Modified: 11 Apr 2025

    The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a "command injection vulnerability."

    Published: 13 Jan 2011
    5.8
    Medium

    CVE-2010-3925

    Last Modified: 11 Apr 2025

    Contents-Mall before 15 does not properly handle passwords, which allows remote attackers to discover the administrative password, and consequently obtain sensitive information or modify data, via unspecified vectors.

    Published: 13 Jan 2011
    2.1
    Low

    CVE-2010-4529

    Last Modified: 11 Apr 2025

    Integer underflow in the irda_getsockopt function in net/irda/af_irda.c in the Linux kernel before 2.6.37 on platforms other than x86 allows local users to obtain potentially sensitive information from kernel heap memory via an IRLMP_ENUMDEVICES getsockopt call.

    Published: 13 Jan 2011
    6.8
    Medium

    CVE-2010-4537

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in CrawlTrack before 3.2.7, when a public stats page is provided, allows remote attackers to execute arbitrary PHP code via unknown vectors.

    Published: 13 Jan 2011
    10
    Critical

    CVE-2011-0262

    Last Modified: 11 Apr 2025

    Buffer overflow in the stringToSeconds function in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via large values of variables to jovgraph.exe.

    Published: 13 Jan 2011
    4.3
    Medium

    CVE-2010-2599

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Research In Motion (RIM) BlackBerry Device Software before 6.0.0 allows remote attackers to cause a denial of service (browser hang) via a crafted web page.

    Published: 12 Jan 2011
    6.8
    Medium

    CVE-2011-0443

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in inc/tinybb-settings.php in tinyBB 1.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 12 Jan 2011
    9.3
    Critical

    CVE-2010-2604

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file.

    Published: 12 Jan 2011
    10
    Critical

    CVE-2010-3912

    Last Modified: 11 Apr 2025

    The supportconfig script in supportutils in SUSE Linux Enterprise 11 SP1 and 10 SP3 does not "disguise passwords" in configuration files, which has unknown impact and attack vectors.

    Published: 12 Jan 2011
    5
    Medium

    CVE-2010-0214

    Last Modified: 11 Apr 2025

    The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which allows remote attackers to obtain sensitive information by reading the HTML source code corresponding to the /admin/sign/DeviceSynch URI.

    Published: 12 Jan 2011
    4.3
    Medium

    CVE-2011-0315

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to the lack of an error page for an application.

    Published: 12 Jan 2011
    7.5
    High

    CVE-2011-0423

    Last Modified: 11 Apr 2025

    The PolyVision RoomWizard with firmware 3.2.3 has a default password of roomwizard for the administrator account, which makes it easier for remote attackers to obtain console access via an HTTP session, a different vulnerability than CVE-2010-0214.

    Published: 12 Jan 2011
    4.3
    Medium

    CVE-2011-0482

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform a cast of an unspecified variable during handling of anchors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document.

    Published: 12 Jan 2011
    2.1
    Low

    CVE-2011-0524

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the NMEA parser (nmea-gen.c) in gypsy 0.8 allow local users to cause a denial of service (crash) via unspecified vectors related to the sprintf function.

    Published: 12 Jan 2011
    4.3
    Medium

    CVE-2010-3926

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Shop.cgi in SGX-SP Final before 11.00 and SGX-SP Final NE before 11.00 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 12 Jan 2011
    9.3
    Critical

    CVE-2011-0027

    Last Modified: 11 Apr 2025

    Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.

    Published: 12 Jan 2011
    1.9
    Low

    CVE-2011-0523

    Last Modified: 11 Apr 2025

    gypsy 0.8 does not properly restrict the files that can be read while running with root privileges, which allows local users to read otherwise restricted files via unspecified vectors.

    Published: 12 Jan 2011
    3.7
    Low

    CVE-2011-1658

    Last Modified: 11 Apr 2025

    ld.so in the GNU C Library (aka glibc or libc6) 2.13 and earlier expands the $ORIGIN dynamic string token when RPATH is composed entirely of this token, which might allow local users to gain privileges by creating a hard link in an arbitrary directory to a (1) setuid or (2) setgid program with this RPATH value, and then executing the program with a crafted value for the LD_PRELOAD environment variable, a different vulnerability than CVE-2010-3847 and CVE-2011-0536. NOTE: it is not expected that any standard operating-system distribution would ship an applicable setuid or setgid program.

    Published: 12 Jan 2011