7.8
    High

    CVE-2011-3315

    Last Modified: 4 Mar 2015

    Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)SU3, and 8.5(x) before 8.5(1)SU2, allows remote attackers to read arbitrary files via a crafted URL, aka Bug IDs CSCth09343 and CSCts44049.

    Source:Sandro Gauci
    Published:27 Oct 2011
    6.8
    Medium

    CVE-2011-3230

    Last Modified: 17 Oct 2011

    Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via a crafted web site.

    Source:Metasploit
    Published:14 Oct 2011
    7.8
    High

    CVE-2011-3192

    Last Modified: 9 Dec 2011

    The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.

    Source:Ramon de C Valle
    Published:20 Aug 2011
    4.3
    Medium

    CVE-2011-3187

    Last Modified: 24 Nov 2014

    The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.

    Source:Jimmy Bandit
    Published:29 Aug 2011
    5
    Medium

    CVE-2011-3182

    Last Modified: 13 Feb 2015

    PHP before 5.3.7 does not properly check the return values of the malloc, calloc, and realloc library functions, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger a buffer overflow by leveraging the ability to provide an arbitrary value for a function argument, related to (1) ext/curl/interface.c, (2) ext/date/lib/parse_date.c, (3) ext/date/lib/parse_iso_intervals.c, (4) ext/date/lib/parse_tz.c, (5) ext/date/lib/timelib.c, (6) ext/pdo_odbc/pdo_odbc.c, (7) ext/reflection/php_reflection.c, (8) ext/soap/php_sdl.c, (9) ext/xmlrpc/libxmlrpc/base64.c, (10) TSRM/tsrm_win32.c, and (11) the strtotime function.

    Source:Maksymilian Arciemowicz
    Published:19 Aug 2011
    10
    Critical

    CVE-2011-3176

    Last Modified: 20 Jul 2012

    Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x4c request.

    Source:Metasploit
    Published:9 Apr 2012
    10
    Critical

    CVE-2011-3175

    Last Modified: 20 Jul 2012

    Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x6c request.

    Source:Metasploit
    Published:9 Apr 2012
    10
    Critical

    CVE-2011-3167

    Last Modified: 20 Jan 2012

    Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1210.

    Source:Metasploit
    Published:2 Nov 2011
    10
    Critical

    CVE-2011-3142

    Last Modified: 9 Mar 2011

    Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute arbitrary code via a long second argument to the ValidateUser method.

    Source:Carlos Mario Penagos Hollmann
    Published:16 Aug 2011
    6.8
    Medium

    CVE-2011-3026

    Last Modified: 11 Apr 2025

    Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.

    Published:16 Feb 2012
    5
    Medium

    CVE-2011-3011

    Last Modified: 23 Mar 2017

    BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, via unspecified vectors.

    Source:Metasploit
    Published:15 Aug 2011
    4.3
    Medium

    CVE-2011-3010

    Last Modified: 24 Feb 2015

    Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCreateNewTopic action, related to the TWiki.WebCreateNewTopicTemplate topic; or (2) the query string to SlideShow.pm in the SlideShowPlugin.

    Source:Mesut Timur
    Published:30 Sept 2011
    6.8
    Medium

    CVE-2011-2975

    Last Modified: 16 Feb 2015

    Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data.

    Source:rouault
    Published:1 Aug 2011
    10
    Critical

    CVE-2011-2963

    Last Modified: 22 Nov 2017

    TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service (crash) via a crafted packet to TCP port 10651.

    Source:Jeremy Brown
    Published:29 Jul 2011
    10
    Critical

    CVE-2011-2960

    Last Modified: 22 Jan 2015

    Heap-based buffer overflow in httpsvr.exe 6.0.5.3 in Sunway ForceControl 6.1 SP1, SP2, and SP3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted URL.

    Source:Dillon Beresford
    Published:29 Jul 2011
    7.8
    High

    CVE-2011-2956

    Last Modified: 7 Feb 2015

    AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of service (system reboot or shutdown) via a signal.

    Source:Knud Erik Hojgaard
    Published:28 Jul 2011
    9.3
    Critical

    CVE-2011-2950

    Last Modified: 17 Sept 2011

    Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted QCP file.

    Source:Metasploit
    Published:18 Aug 2011
    7.5
    High

    CVE-2011-2944

    Last Modified: 16 Mar 2012

    SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Danny Moules
    Published:12 Aug 2014
    4.3
    Medium

    CVE-2011-2938

    Last Modified: 8 Jun 2018

    Multiple cross-site scripting (XSS) vulnerabilities in filter_api.php in MantisBT before 1.2.7 allow remote attackers to inject arbitrary web script or HTML via a parameter, as demonstrated by the project_id parameter to search.php.

    Source:Net.Edit0r
    Published:21 Sept 2011
    9.8
    Critical

    CVE-2011-2921

    Last Modified: 3 Sept 2019

    ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.

    Source:Metasploit
    Published:19 Nov 2019
    5.5
    Medium

    CVE-2011-2918

    Last Modified: 1 Sept 2011

    The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with PERF_COUNT_SW_CPU_CLOCK events, which allows local users to cause a denial of service (system hang) via a crafted application.

    Source:Vince Weaver
    Published:22 Jul 2011
    7.5
    High

    CVE-2011-2917

    Last Modified: 31 Oct 2016

    SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the zorder parameter.

    Source:KraL BeNiM
    Published:8 Dec 2011
    7.5
    High

    CVE-2011-2900

    Last Modified: 12 Aug 2011

    Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.

    Source:G13
    Published:5 Aug 2011
    6.8
    Medium

    CVE-2011-2894

    Last Modified: 11 Apr 2025

    Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrusted code by (1) serializing a java.lang.Proxy instance and using InvocationHandler, or (2) accessing internal AOP interfaces, as demonstrated using deserialization of a DefaultListableBeanFactory instance to execute arbitrary commands via the java.lang.Runtime class.

    Published:9 Sept 2011
    9.3
    Critical

    CVE-2011-2882

    Last Modified: 31 Aug 2011

    Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 allows remote attackers to execute arbitrary code via crafted HTTP header data.

    Source:Metasploit
    Published:21 Jul 2011
    6.8
    Medium

    CVE-2011-2841

    Last Modified: 4 Oct 2011

    Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.

    Source:Mario Gomes
    Published:17 Sept 2011
    5
    Medium

    CVE-2011-2780

    Last Modified: 29 Jan 2015

    Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability than CVE-2011-2744.

    Source:Wireghoul
    Published:19 Jul 2011
    4.4
    Medium

    CVE-2011-2777

    Last Modified: 10 Dec 2011

    samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBUS_SESSION_BUS_ADDRESS environment variable containing commands.

    Source:otr
    Published:29 Aug 2012
    7.5
    High

    CVE-2011-2763

    Last Modified: 1 Sept 2011

    The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a modified request to the LSRoom_Remoting.doCommand function in gateway.php.

    Source:Spencer McIntyre
    Published:2 Sept 2011
    5
    Medium

    CVE-2011-2757

    Last Modified: 7 Jul 2011

    Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the FILENAME parameter. NOTE: this might overlap the US-CERT VU#543310 issue.

    Source:@ygoltsev
    Published:17 Jul 2011
    5
    Medium

    CVE-2011-2755

    Last Modified: 7 Jul 2011

    Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary files via unspecified vectors.

    Source:@ygoltsev
    Published:17 Jul 2011
    7.5
    High

    CVE-2011-2751

    Last Modified: 5 Jul 2012

    SQL injection vulnerability in Parodia before 6.809 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Source:Carlos Mario Penagos Hollmann
    Published:17 Jul 2011
    6.5
    Medium

    CVE-2011-2745

    Last Modified: 29 Jan 2015

    upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.

    Source:Wireghoul
    Published:27 Jul 2011
    6.8
    Medium

    CVE-2011-2744

    Last Modified: 29 Jan 2015

    Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the action parameter to the default URI.

    Source:Wireghoul
    Published:19 Jul 2011
    4.3
    Medium

    CVE-2011-2743

    Last Modified: 29 Jan 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the action parameter to (1) the default URI or (2) includes/javascript.php, or the (3) title or (4) body parameter to admin/help.php.

    Source:Wireghoul
    Published:19 Jul 2011
    4.3
    Medium

    CVE-2011-2732

    Last Modified: 20 Feb 2015

    CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the spring-security-redirect parameter.

    Source:David Mas
    Published:9 Sept 2011
    6.8
    Medium

    CVE-2011-2702

    Last Modified: 10 Oct 2016

    Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allows context-dependent attackers to execute arbitrary code via a negative length parameter to (1) memcpy-ssse3-rep.S, (2) memcpy-ssse3.S, or (3) memset-sse2.S in sysdeps/i386/i686/multiarch/, which triggers an out-of-bounds read, as demonstrated using the memcpy function.

    Source:c0ntex
    Published:27 Oct 2014
    6.8
    Medium

    CVE-2011-2657

    Last Modified: 11 Jul 2012

    Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in LaunchHelp.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary commands via a pathname in the first argument.

    Source:Metasploit
    Published:26 Jul 2012
    10
    Critical

    CVE-2011-2653

    Last Modified: 15 Aug 2012

    Directory traversal vulnerability in the rtrlet component in Novell ZENworks Asset Management (ZAM) 7.5 allows remote attackers to execute arbitrary code by uploading an executable file.

    Source:Metasploit
    Published:8 Dec 2011
    5
    Medium

    CVE-2011-2641

    Last Modified: 14 Jun 2011

    Opera 11.11 allows remote attackers to cause a denial of service (application crash) by setting the FACE attribute of a FONT element within an IFRAME element after changing the SRC attribute of this IFRAME element to an about:blank value.

    Source:echo
    Published:1 Jul 2011
    10
    Critical

    CVE-2011-2628

    Last Modified: 7 Oct 2011

    Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to page unload.

    Source:Jose A. Vazquez
    Published:1 Jul 2011
    10
    Critical

    CVE-2011-2595

    Last Modified: 11 Oct 2011

    Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code via a long id parameter in a (1) String or (2) Int tag in a FotoSlate Project (aka PLP) file.

    Source:Metasploit
    Published:14 Sept 2011
    7.8
    High

    CVE-2011-2577

    Last Modified: 19 Sept 2011

    Unspecified vulnerability in Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs, when using software versions before TC 4.0.0 or F9.1, allows remote attackers to cause a denial of service (crash) via a crafted SIP packet to port 5060 or 5061, aka Bug ID CSCtq46500.

    Source:Sense of Security
    Published:31 Aug 2011
    Unknown

    CVE-2011-2553

    https://github.com/carlosrpastrana/cve-2011-2553

    3.5
    Low

    CVE-2011-2544

    Last Modified: 19 Sept 2011

    Cross-site scripting (XSS) vulnerability in the web interface in Cisco TelePresence System MXP Series F9.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a crafted Call ID, as demonstrated by resultant cross-site request forgery (CSRF) attacks that change passwords or cause a denial of service, aka Bug ID CSCtq46488.

    Source:Sense of Security
    Published:23 Sept 2011
    9
    Critical

    CVE-2011-2543

    Last Modified: 19 Sept 2011

    Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote authenticated users to cause a denial of service (endpoint reboot or process crash) or possibly execute arbitrary code via a long location parameter to the getxml program, aka Bug ID CSCtq46496.

    Source:Sense of Security
    Published:23 Sept 2011
    9.8
    Critical

    CVE-2011-2523

    Last Modified: 16 Jul 2021

    vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

    Source:HerculesRD
    Published:4 Jul 2011
    6.8
    Medium

    CVE-2011-2522

    Last Modified: 8 Aug 2011

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program.

    Source:Narendra Shinde
    Published:26 Jul 2011
    7.5
    High

    CVE-2011-2506

    Last Modified: 24 Jul 2011

    setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.

    Source:Mango
    Published:14 Jul 2011
    6.4
    Medium

    CVE-2011-2505

    Last Modified: 24 Jul 2011

    libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

    Source:Mango
    Published:14 Jul 2011