4.3
    Medium

    CVE-2011-1714

    Last Modified: 9 Dec 2013

    Cross-site scripting (XSS) vulnerability in framework/source/resource/qx/test/jsonp_primitive.php in QooxDoo 1.3 and possibly other versions, as used in eyeOS 2.2 and 2.3, and possibly other products allows remote attackers to inject arbitrary web script or HTML via the callback parameter.

    Source:AutoSec Tools
    Published:18 Apr 2011
    4.3
    Medium

    CVE-2011-1682

    Last Modified: 16 Mar 2012

    Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Cyber-Crystal
    Published:13 Apr 2011
    4.3
    Medium

    CVE-2011-1671

    Last Modified: 15 Dec 2014

    Cross-site scripting (XSS) vulnerability in app/controllers/todos_controller.rb in Tracks 1.7.2, 2.0RC2, and 2.0devel allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to todos/tag/. NOTE: some of these details are obtained from third party information.

    Source:Mesut Timur
    Published:10 Apr 2011
    4.3
    Medium

    CVE-2011-1670

    Last Modified: 16 Dec 2014

    Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the subject parameter to post_url/edit.

    Source:High-Tech Bridge SA
    Published:10 Apr 2011
    5
    Medium

    CVE-2011-1669

    Last Modified: 5 Apr 2011

    Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary files via ..%2F (encoded dot dot) sequences in the url parameter.

    Source:AutoSec Tools
    Published:10 Apr 2011
    4.3
    Medium

    CVE-2011-1668

    Last Modified: 16 Dec 2014

    Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Source:Antu Sanadi
    Published:10 Apr 2011
    7.5
    High

    CVE-2011-1667

    Last Modified: 4 Apr 2011

    SQL injection vulnerability in index.php in Anzeigenmarkt 2011 allows remote attackers to execute arbitrary SQL commands via the q parameter in a list action.

    Source:Easy Laster
    Published:10 Apr 2011
    5
    Medium

    CVE-2011-1665

    Last Modified: 31 Mar 2011

    PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain backup SQL files via a direct request for predictable filenames in cache/backup/.

    Source:KedAns-Dz
    Published:10 Apr 2011
    Unknown

    CVE-2011-1656

    https://www.exploit-db.com/exploits/35919

    10
    Critical

    CVE-2011-1653

    Last Modified: 3 Oct 2011

    Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attackers to execute arbitrary SQL commands via vectors involving the (1) UnAssignFunctionalRoles, (2) UnassignAdminRoles, (3) DeleteFilter, (4) NonAssignedUserList, (5) DeleteReportLayout, (6) DeleteReports, and (7) RegenerateReport stored procedures.

    Source:Metasploit
    Published:15 Apr 2011
    7.8
    High

    CVE-2011-1613

    Last Modified: 26 Sept 2012

    Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 6.0 before 6.0.200.0, 7.0 before 7.0.98.216, and 7.0.1xx before 7.0.112.0 allows remote attackers to cause a denial of service (device reload) via a sequence of ICMP packets, aka Bug ID CSCth74426.

    Source:Daniel Smith
    Published:3 May 2011
    8.5
    High

    CVE-2011-1609

    Last Modified: 2 Jan 2015

    SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtg85647.

    Source:Alberto Revelli
    Published:3 May 2011
    9.3
    Critical

    CVE-2011-1591

    Last Modified: 22 Nov 2011

    Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allows remote attackers to execute arbitrary code via a crafted .pcap file.

    Source:ipv
    Published:15 Apr 2011
    5.8
    Medium

    CVE-2011-1575

    Last Modified: 11 Apr 2025

    The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

    Published:23 May 2011
    6.8
    Medium

    CVE-2011-1574

    Last Modified: 15 Nov 2016

    Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in libmodplug before 0.8.8.2 allows remote attackers to execute arbitrary code via a crafted S3M file.

    Source:Metasploit
    Published:7 Apr 2011
    6.8
    Medium

    CVE-2011-1571

    Last Modified: 8 Apr 2012

    Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.

    Source:Spencer McIntyre
    Published:7 May 2011
    5
    Medium

    CVE-2011-1569

    Last Modified: 20 Mar 2011

    download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web root via (1) a trailing ".", (2) a trailing space, or (3) mixed case in the FileNameAttach parameter.

    Source:AJAX Security Team
    Published:5 Apr 2011
    10
    Critical

    CVE-2011-1568

    Last Modified: 27 Oct 2016

    Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated using the RMS Reports Delete command, related to the logging of messages to GSST.LOG. NOTE: some of these details are obtained from third party information.

    Source:Luigi Auriemma
    Published:5 Apr 2011
    10
    Critical

    CVE-2011-1567

    Last Modified: 9 Jun 2011

    Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted (1) ListAll, (2) Write File, (3) ReadFile, (4) Delete, (5) RenameFile, and (6) FileInfo commands in an 0xd opcode; (7) the Add, (8) ReadFile, (9) Write File, (10) Rename, (11) Delete, and (12) Add commands in an RMS report templates (0x7) opcode; and (13) 0x4 command in an STDREP request (0x8) opcode to TCP port 12401.

    Source:Metasploit
    Published:5 Apr 2011
    10
    Critical

    CVE-2011-1566

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to execute arbitrary programs via ..\ (dot dot backslash) sequences in opcodes (1) 0xa and (2) 0x17 to TCP port 12397.

    Source:Luigi Auriemma
    Published:5 Apr 2011
    10
    Critical

    CVE-2011-1565

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to (1) read (opcode 0x3) or (2) create or write (opcode 0x2) arbitrary files via ..\ (dot dot backslash) sequences to TCP port 12401.

    Source:Luigi Auriemma
    Published:5 Apr 2011
    10
    Critical

    CVE-2011-1564

    Last Modified: 22 Mar 2011

    Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via crafted (1) On_FC_MISC_FCS_MSGBROADCAST and (2) On_FC_MISC_FCS_MSGSEND packets, which trigger a heap-based buffer overflow.

    Source:Luigi Auriemma
    Published:5 Apr 2011
    10
    Critical

    CVE-2011-1563

    Last Modified: 22 Mar 2011

    Multiple stack-based buffer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via (1) a long username in an On_FC_CONNECT_FCS_LOGIN packet, and crafted (2) On_FC_CTAGLIST_FCS_CADDTAG, (3) On_FC_CTAGLIST_FCS_CDELTAG, (4) On_FC_CTAGLIST_FCS_ADDTAGMS, (5) On_FC_RFUSER_FCS_LOGIN, (6) unspecified "On_FC_BINFILE_FCS_*FILE", (7) On_FC_CGETTAG_FCS_GETTELEMETRY, (8) On_FC_CGETTAG_FCS_GETCHANNELTELEMETRY, (9) On_FC_CGETTAG_FCS_SETTELEMETRY, (10) On_FC_CGETTAG_FCS_SETCHANNELTELEMETRY, and (11) On_FC_SCRIPT_FCS_STARTPROG packets to port 910.

    Source:Luigi Auriemma
    Published:5 Apr 2011
    7.5
    High

    CVE-2011-1557

    Last Modified: 16 Dec 2014

    SQL injection vulnerability in ICloudCenter ICJobSite 1.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter to an unspecified component, a different vulnerability than CVE-2011-1546. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:RoAd_KiLlEr
    Published:1 Apr 2011
    6.8
    Medium

    CVE-2011-1556

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in plugins/pdfClasses/pdfgen.php in Andy's PHP Knowledgebase (Aphpkb) 0.95.4 allows remote attackers to execute arbitrary SQL commands via the pdfa parameter.

    Source:AutoSec Tools
    Published:1 Apr 2011
    6.8
    Medium

    CVE-2011-1547

    Last Modified: 8 May 2011

    Multiple stack consumption vulnerabilities in the kernel in NetBSD 4.0, 5.0 before 5.0.3, and 5.1 before 5.1.1, when IPsec is enabled, allow remote attackers to cause a denial of service (memory corruption and panic) or possibly have unspecified other impact via a crafted (1) IPv4 or (2) IPv6 packet with nested IPComp headers.

    Source:Tavis Ormandy
    Published:9 May 2011
    7.5
    High

    CVE-2011-1546

    Last Modified: 6 Jan 2017

    Multiple SQL injection vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.3 allow remote attackers to execute arbitrary SQL commands via the s parameter to (1) a_viewusers.php or (2) keysearch.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (3) id or (4) start parameter to pending.php, or the (5) aid parameter to a_authordetails.php. NOTE: some of these details are obtained from third party information.

    Source:Mark Stanislav
    Published:1 Apr 2011
    9.3
    Critical

    CVE-2011-1525

    Last Modified: 21 Mar 2011

    Heap-based buffer overflow in rvrender.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted frame in an Internet Video Recording (IVR) file.

    Source:Luigi Auriemma
    Published:6 Apr 2011
    4.3
    Medium

    CVE-2011-1524

    Last Modified: 12 Nov 2016

    Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to inject arbitrary web script or HTML via the username field, as demonstrated by injecting an IFRAME element into the event log, a different vulnerability than CVE-2011-0545.

    Source:Nikolas Sotiriu
    Published:28 Mar 2011
    10
    Critical

    CVE-2011-1519

    Last Modified: 30 Nov 2011

    The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.

    Source:Alexey Sintsov
    Published:25 Mar 2011
    7.6
    High

    CVE-2011-1516

    Last Modified: 9 May 2012

    The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of osascript to send Apple events to the launchd daemon, a related issue to CVE-2008-7303.

    Source:Core Security
    Published:15 Nov 2011
    7.5
    High

    CVE-2011-1513

    Last Modified: 4 Mar 2015

    Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.

    Source:Matt Bergin
    Published:4 Nov 2011
    6.4
    Medium

    CVE-2011-1511

    Last Modified: 12 May 2011

    Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 and 3.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to Administration.

    Source:Core Security
    Published:19 Jul 2011
    4.6
    Medium

    CVE-2011-1496

    Last Modified: 12 Jul 2015

    tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a filename to the -S command-line option.

    Source:ph0x90bic
    Published:18 Apr 2011
    5
    Medium

    CVE-2011-1487

    Last Modified: 16 Dec 2014

    The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

    Source:mmartinec
    Published:30 Mar 2011
    6.9
    Medium

    CVE-2011-1485

    Last Modified: 20 Oct 2014

    Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privileges by executing a setuid program from pkexec, related to the use of the effective user ID instead of the real user ID.

    Source:Metasploit
    Published:19 Apr 2011
    4.7
    Medium

    CVE-2011-1479

    Last Modified: 6 Sept 2016

    Double free vulnerability in the inotify subsystem in the Linux kernel before 2.6.39 allows local users to cause a denial of service (system crash) via vectors involving failed attempts to create files. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-4250.

    Source:anonymous
    Published:5 Apr 2011
    5
    Medium

    CVE-2011-1475

    Last Modified: 11 Apr 2025

    The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

    Published:6 Apr 2011
    5
    Medium

    CVE-2011-1473

    Last Modified: 11 Apr 2025

    OpenSSL before 0.9.8l, and 0.9.8m through 1.x, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-5094. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment

    Published:13 Mar 2011
    4.3
    Medium

    CVE-2011-1471

    Last Modified: 8 Dec 2014

    Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls.

    Source:TorokAlpar
    Published:27 Jul 2009
    4.3
    Medium

    CVE-2011-1470

    Last Modified: 8 Dec 2014

    The Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a ziparchive stream that is not properly handled by the stream_get_contents function.

    Source:paulgao
    Published:20 Dec 2010
    4.3
    Medium

    CVE-2011-1468

    Last Modified: 8 Dec 2014

    Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might allow remote attackers to cause a denial of service (memory consumption) via (1) plaintext data to the openssl_encrypt function or (2) ciphertext data to the openssl_decrypt function.

    Source:dovbysh
    Published:21 Feb 2011
    5
    Medium

    CVE-2011-1467

    Last Modified: 8 Dec 2014

    Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument, a related issue to CVE-2010-4409.

    Source:thoger
    Published:7 Dec 2010
    4.3
    Medium

    CVE-2011-1427

    Last Modified: 1 Dec 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 5.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Language parameter to Pages/login.aspx, (2) HeaderWarning parameter to Troubleshooting/DiagnosticReport.asp, or (3) User-Agent header to troubleshooting/speedtest.asp.

    Source:Dionach
    Published:15 Mar 2011
    5.1
    Medium

    CVE-2011-1425

    Last Modified: 18 Oct 2011

    xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

    Source:Metasploit
    Published:31 Mar 2011
    4.3
    Medium

    CVE-2011-1398

    Last Modified: 1 Dec 2016

    The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

    Source:Mr. Tokumaru
    Published:6 Nov 2011
    7.1
    High

    CVE-2011-1350

    Last Modified: 21 Dec 2016

    The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an application that uses a crafted length parameter in a request to the pvrsrvkm device.

    Source:Geremy Condra
    Published:5 Feb 2013
    9.3
    Critical

    CVE-2011-1276

    Last Modified: 26 Aug 2011

    Buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Excel spreadsheet, related to improper validation of record information, aka "Excel Buffer Overrun Vulnerability."

    Source:webDEViL
    Published:16 Jun 2011
    7.7
    High

    CVE-2011-1271

    Last Modified: 9 Jan 2015

    The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle expressions related to null strings, which allows context-dependent attackers to bypass intended access restrictions, and consequently execute arbitrary code, in opportunistic circumstances by leveraging a crafted application, as demonstrated by (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework JIT Optimization Vulnerability."

    Source:Brian Mancini
    Published:10 May 2011
    9.3
    Critical

    CVE-2011-1260

    Last Modified: 17 Jun 2011

    Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Layout Memory Corruption Vulnerability."

    Source:Metasploit
    Published:16 Jun 2011