8.8
    High

    CVE-2011-2462

    Last Modified: 14 Jan 2012

    Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.

    Source:Metasploit
    Published:6 Dec 2011
    4.3
    Medium

    CVE-2011-2461

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Adobe Flex SDK 3.x and 4.x before 4.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to the loading of modules from different domains.

    Published:1 Dec 2011
    9.3
    Critical

    CVE-2011-2443

    Last Modified: 2 Oct 2011

    Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted (1) .grd or (2) .abr file, a related issue to CVE-2010-1296.

    Source:LiquidWorm
    Published:4 Oct 2011
    7.5
    High

    CVE-2011-2404

    Last Modified: 20 Aug 2011

    A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via unspecified vectors, a different vulnerability than CVE-2011-4786 and CVE-2011-4787.

    Source:Metasploit
    Published:11 Aug 2011
    6.5
    Medium

    CVE-2011-2403

    Last Modified: 6 Feb 2015

    SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Source:anonymous
    Published:1 Aug 2011
    9.3
    Critical

    CVE-2011-2386

    Last Modified: 5 Jun 2011

    VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary code via a (1) vws and (2) vwr file with an invalid Type property, which triggers an untrusted pointer dereference.

    Source:Metasploit
    Published:8 Jun 2011
    10
    Critical

    CVE-2011-2371

    Last Modified: 12 Oct 2017

    Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object.

    Source:ryujin
    Published:21 Jun 2011
    4.3
    Medium

    CVE-2011-2357

    Last Modified: 7 Feb 2015

    Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs to be opened, then loading a URI to the targeted domain into the current tab, or (2) making two startActivity function calls beginning with the targeted domain's URI followed by the malicious Javascript while the UI focus is still associated with the targeted domain.

    Source:Roee Hay
    Published:12 Aug 2011
    5.8
    Medium

    CVE-2011-2260

    Last Modified: 20 Jul 2011

    Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Administration.

    Source:Sense of Security
    Published:19 Jul 2011
    9.3
    Critical

    CVE-2011-2217

    Last Modified: 10 Jun 2012

    Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.237, as used in VI Client (aka VMware Infrastructure Client) 2.0.2 before Build 230598 and 2.5 before Build 204931 in VMware Infrastructure 3, do not properly handle attempted initialization within Internet Explorer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document.

    Source:Metasploit
    Published:6 Jun 2011
    6.4
    Medium

    CVE-2011-2202

    Last Modified: 21 Jan 2015

    The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."

    Source:Krzysztof Kotowicz
    Published:12 Jun 2011
    4.3
    Medium

    CVE-2011-2201

    Last Modified: 20 Jan 2015

    The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input.

    Source:dst
    Published:14 Sept 2011
    9.3
    Critical

    CVE-2011-2194

    Last Modified: 15 Nov 2016

    Integer overflow in the XSPF playlist parser in VideoLAN VLC media player 0.8.5 through 1.1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a heap-based buffer overflow.

    Source:TecR0c
    Published:24 Jun 2011
    7.5
    High

    CVE-2011-2189

    Last Modified: 19 Mar 2015

    net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.

    Source:Serge Hallyn
    Published:16 Feb 2011
    4
    Medium

    CVE-2011-2183

    Last Modified: 6 Sept 2016

    Race condition in the scan_get_next_rmap_item function in mm/ksm.c in the Linux kernel before 2.6.39.3, when Kernel SamePage Merging (KSM) is enabled, allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted application.

    Source:Andrea Righi
    Published:2 Jun 2011
    4.3
    Medium

    CVE-2011-2179

    Last Modified: 18 Jan 2015

    Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action.

    Source:Stefan Schurtz
    Published:14 Jun 2011
    6.8
    Medium

    CVE-2011-2165

    Last Modified: 30 Jun 2015

    The STARTTLS implementation in WatchGuard XCS 9.0 and 9.1 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

    Source:Security-Assessment.com
    Published:23 May 2011
    10
    Critical

    CVE-2011-2140

    Last Modified: 10 Feb 2012

    Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2135, CVE-2011-2417, and CVE-2011-2425.

    Source:Metasploit
    Published:9 Aug 2011
    5
    Medium

    CVE-2011-2132

    Last Modified: 9 Feb 2015

    Adobe Flash Media Server (FMS) before 3.5.7, and 4.x before 4.0.3, allows attackers to cause a denial of service (memory corruption) via unspecified vectors.

    Source:Knud Erik Hojgaard
    Published:11 Aug 2011
    9.3
    Critical

    CVE-2011-2131

    Last Modified: 25 Aug 2011

    Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GIF file.

    Source:Francis Provencher
    Published:11 Aug 2011
    10
    Critical

    CVE-2011-2110

    Last Modified: 20 Jun 2012

    Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in June 2011.

    Source:Metasploit
    Published:14 Jun 2011
    9.3
    Critical

    CVE-2011-2089

    Last Modified: 11 May 2011

    Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICONICS BizViz 9.x before 9.22 and GENESIS32 9.x before 9.22 allows remote attackers to execute arbitrary code via a long string in the argument. NOTE: some of these details are obtained from third party information.

    Source:Metasploit
    Published:13 May 2011
    7.6
    High

    CVE-2011-2039

    Last Modified: 7 Jun 2011

    The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a certain ActiveX control in vpnweb.ocx, aka Bug ID CSCsy00904.

    Source:Metasploit
    Published:2 Jun 2011
    9.8
    Critical

    CVE-2011-2013

    Last Modified: 6 Mar 2015

    Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed port, aka "Reference Counter Overflow Vulnerability."

    Source:anonymous
    Published:8 Nov 2011
    5
    Medium

    CVE-2011-2007

    Last Modified: 3 Mar 2015

    Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."

    Source:Luigi Auriemma
    Published:12 Oct 2011
    7.8
    High

    CVE-2011-2005

    Last Modified: 10 Oct 2012

    afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."

    Source:Metasploit
    Published:12 Oct 2011
    9.3
    Critical

    CVE-2011-2003

    Last Modified: 13 Oct 2011

    Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted .fon file, aka "Font Library File Buffer Overrun Vulnerability."

    Source:Byoungyoung Lee
    Published:12 Oct 2011
    9.3
    Critical

    CVE-2011-1999

    Last Modified: 28 Feb 2015

    Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arbitrary code via vectors involving a "dereferenced memory address," aka "Select Element Remote Code Execution Vulnerability."

    Source:Ivan Fratric
    Published:12 Oct 2011
    9.3
    Critical

    CVE-2011-1996

    Last Modified: 10 Jan 2013

    Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."

    Source:Metasploit
    Published:12 Oct 2011
    7.1
    High

    CVE-2011-1985

    Last Modified: 23 Oct 2011

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer De-reference Vulnerability."

    Source:KiDebug
    Published:12 Oct 2011
    7.2
    High

    CVE-2011-1984

    Last Modified: 13 Sept 2011

    WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability."

    Source:Core Security
    Published:15 Sept 2011
    4.3
    Medium

    CVE-2011-1976

    Last Modified: 8 Feb 2015

    Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XSS Vulnerability."

    Source:Adam Bixby
    Published:10 Aug 2011
    7.2
    High

    CVE-2011-1974

    Last Modified: 31 Jan 2017

    NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI Elevation of Privilege Vulnerability."

    Source:Tomislav Paskalev
    Published:10 Aug 2011
    7.1
    High

    CVE-2011-1965

    Last Modified: 15 Oct 2011

    Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server, aka "TCP/IP QOS Denial of Service Vulnerability."

    Source:Byoungyoung Lee
    Published:10 Aug 2011
    4.3
    Medium

    CVE-2011-1956

    Last Modified: 26 Jan 2015

    The bytes_repr_len function in Wireshark 1.4.5 uses an incorrect pointer argument, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via arbitrary TCP traffic.

    Source:rouli
    Published:6 Jun 2011
    9.3
    Critical

    CVE-2011-1944

    Last Modified: 17 Jan 2015

    Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.

    Source:Chris Evans
    Published:27 May 2011
    9.8
    Critical

    CVE-2011-1939

    Last Modified: 14 Jan 2015

    SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

    Source:Anthony Ferrara
    Published:26 Nov 2019
    7.5
    High

    CVE-2011-1938

    Last Modified: 29 May 2011

    Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket.

    Source:Marek Kroemeke
    Published:23 May 2011
    9.8
    Critical

    CVE-2011-1930

    Last Modified: 14 Jan 2015

    In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.

    Source:maximilian attems
    Published:14 Nov 2019
    4
    Medium

    CVE-2011-1892

    Last Modified: 20 Sept 2011

    Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability."

    Source:Nicolas Gregoire
    Published:15 Sept 2011
    4.7
    Medium

    CVE-2011-1872

    Last Modified: 14 Jun 2011

    Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malformed machine instructions in a VMBus packet, aka "VMBus Persistent DoS Vulnerability."

    Source:Core Security
    Published:16 Jun 2011
    10
    Critical

    CVE-2011-1866

    Last Modified: 30 Jun 2011

    Buffer overflow in omniinet.exe in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to execute arbitrary code via a crafted request, related to the EXEC_CMD functionality.

    Source:Core Security
    Published:1 Jul 2011
    10
    Critical

    CVE-2011-1865

    Last Modified: 29 Jun 2011

    Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to execute arbitrary code via a request containing crafted parameters.

    Source:Core Security
    Published:1 Jul 2011
    4.3
    Medium

    CVE-2011-1838

    Last Modified: 11 Jan 2015

    Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via the origurl parameter to a (1) view script or (2) login script.

    Source:Mesut Timur
    Published:20 May 2011
    8.8
    High

    CVE-2011-1774

    Last Modified: 18 Oct 2011

    WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted web site. NOTE: this may overlap CVE-2011-1425.

    Source:Metasploit
    Published:21 Jul 2011
    2.6
    Low

    CVE-2011-1772

    Last Modified: 9 Jan 2015

    Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.

    Source:Dr. Marian Ventuneac
    Published:22 Feb 2011
    6.8
    Medium

    CVE-2011-1761

    Last Modified: 21 May 2011

    Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ABC file. NOTE: some of these details are obtained from third party information.

    Source:epiphant
    Published:28 Apr 2011
    7.2
    High

    CVE-2011-1760

    Last Modified: 3 Jan 2015

    utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to conduct eval injection attacks and gain privileges via shell metacharacters in the -e argument.

    Source:Stephane Chauveau
    Published:26 Apr 2011
    4.3
    Medium

    CVE-2011-1723

    Last Modified: 19 Dec 2014

    Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to projects/hg-helloworld/news/. NOTE: some of these details are obtained from third party information.

    Source:Mesut Timur
    Published:19 Apr 2011
    5
    Medium

    CVE-2011-1715

    Last Modified: 9 Dec 2013

    Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to read arbitrary files via ..%2f (encoded dot dot) sequences in the file parameter.

    Source:AutoSec Tools
    Published:18 Apr 2011