9.3
    Critical

    CVE-2011-1255

    Last Modified: 14 Jul 2017

    The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Time Element Memory Corruption Vulnerability."

    Source:Ciph3r
    Published:16 Jun 2011
    7.2
    High

    CVE-2011-1249

    Last Modified: 24 Apr 2017

    The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."

    Source:fb1h2s
    Published:16 Jun 2011
    9.3
    Critical

    CVE-2011-1248

    Last Modified: 13 Sept 2011

    WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."

    Source:Luigi Auriemma
    Published:13 May 2011
    7.2
    High

    CVE-2011-1237

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."

    Published:13 Apr 2011
    9
    Critical

    CVE-2011-1220

    Last Modified: 12 Jun 2011

    Stack-based buffer overflow in lcfd.exe in Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 allows remote authenticated users to execute arbitrary code via a long opts field.

    Source:Metasploit
    Published:2 Jun 2011
    9.3
    Critical

    CVE-2011-1213

    Last Modified: 24 Jun 2011

    Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.

    Source:Metasploit
    Published:31 May 2011
    10
    Critical

    CVE-2011-1206

    Last Modified: 19 Apr 2011

    Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) allows remote attackers to execute arbitrary code via a crafted LDAP request. NOTE: some of these details are obtained from third party information.

    Source:Francis Provencher
    Published:21 Apr 2011
    2.1
    Low

    CVE-2011-1159

    Last Modified: 15 Nov 2014

    acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.

    Source:Vasiliy Kulikov
    Published:19 Jan 2011
    4.3
    Medium

    CVE-2011-1143

    Last Modified: 3 Dec 2014

    epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file.

    Source:Buildbot Builder
    Published:1 Mar 2011
    5
    Medium

    CVE-2011-1137

    Last Modified: 29 Aug 2017

    Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memory consumption leading to OOM kill) via a malformed SSH message.

    Source:kingcope
    Published:11 Mar 2011
    4.3
    Medium

    CVE-2011-1106

    Last Modified: 26 Nov 2014

    Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to inject arbitrary web script or HTML via the authReasonCode parameter in an OpenDatabase action.

    Source:andrew
    Published:1 Mar 2011
    6.5
    Medium

    CVE-2011-1100

    Last Modified: 12 Feb 2011

    Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) findfid, (2) id, (3) selectfcat, (4) selectfmon, or (5) selectftag parameter in an images action.

    Source:LiquidWorm
    Published:25 Feb 2011
    5.8
    Medium

    CVE-2011-1099

    Last Modified: 6 Mar 2011

    Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls before 1.0.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the p parameter in a preview action to index.php, or (2) delete arbitrary files via a .. (dot dot) in the p parameter in a delete action to index.php.

    Source:Mark Stanislav
    Published:9 Mar 2011
    7.5
    High

    CVE-2011-1092

    Last Modified: 18 Mar 2016

    Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive memory via a large third argument to the shmop_read function.

    Source:Jose Carlos Norte
    Published:8 Mar 2011
    4.9
    Medium

    CVE-2011-1083

    Last Modified: 6 Sept 2016

    The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.

    Source:Nelson Elhage
    Published:25 Feb 2011
    4.9
    Medium

    CVE-2011-1082

    Last Modified: 6 Sept 2016

    fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.

    Source:Nelson Elhage
    Published:5 Feb 2011
    5
    Medium

    CVE-2011-1081

    Last Modified: 3 Dec 2014

    modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (aka MODRDN operation) that contains an empty value for the OldDN field.

    Source:Serge Dubrouski
    Published:3 Jan 2011
    5.1
    Medium

    CVE-2011-1071

    Last Modified: 12 Nov 2016

    The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.

    Source:Simon Berry-Byrne
    Published:5 Aug 2010
    4.3
    Medium

    CVE-2011-1062

    Last Modified: 27 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in include/html/header.php in TaskFreak! 0.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) sContext, (2) sort, (3) dir, and (4) show parameters in a save action to index.php; the (5) dir and (6) show parameters to print_list.php; and the (7) HTTP referer header to rss.php. NOTE: some of these details are obtained from third party information.

    Source:LiquidWorm
    Published:22 Feb 2011
    7.5
    High

    CVE-2011-1060

    Last Modified: 25 Nov 2014

    SQL injection vulnerability in the member function in classes/member.php in WSN Guest 1.24 allows remote attackers to execute arbitrary SQL commands via the wsnuser cookie to index.php.

    Source:Aliaksandr Hartsuyeu
    Published:22 Feb 2011
    7.5
    High

    CVE-2011-1055

    Last Modified: 15 Feb 2011

    SQL injection vulnerability in api/ice_media.cfc in Lingxia I.C.E CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the session.user_id parameter to media.cfm.

    Source:mr_me
    Published:21 Feb 2011
    7.5
    High

    CVE-2011-1048

    Last Modified: 9 Feb 2011

    SQL injection vulnerability in product.php in MihanTools 1.33 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:WHITE_DEVIL
    Published:21 Feb 2011
    7.5
    High

    CVE-2011-1047

    Last Modified: 24 Feb 2011

    Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) search_max parameter in a search action to index.php, which is not properly handled by wpf.class.php, (2) id parameter in an editpost action to index.php, which is not properly handled by wpf-post.php, or (3) topic parameter to feed.php.

    Source:High-Tech Bridge SA
    Published:21 Feb 2011
    4.3
    Medium

    CVE-2011-1038

    Last Modified: 25 Nov 2014

    Multiple cross-site scripting (XSS) vulnerabilities in stconf.nsf in the server in IBM Lotus Sametime 8.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the messageString parameter in a WebMessage action or (2) the PATH_INFO.

    Source:Dave Daly
    Published:22 Feb 2011
    3.6
    Low

    CVE-2011-1021

    Last Modified: 10 Oct 2016

    drivers/acpi/debugfs.c in the Linux kernel before 3.0 allows local users to modify arbitrary kernel memory locations by leveraging root privileges to write to the /sys/kernel/debug/acpi/custom_method file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4347.

    Source:Jon Oberheide
    Published:22 Feb 2011
    4.6
    Medium

    CVE-2011-1020

    Last Modified: 30 Mar 2017

    The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc directory tree of a process after this process performs an exec of a setuid program, which allows local users to obtain sensitive information or cause a denial of service via open, lseek, read, and write system calls.

    Source:halfdog
    Published:7 Feb 2011
    10
    Critical

    CVE-2011-1018

    Last Modified: 27 Nov 2014

    logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.

    Source:Dominik George
    Published:16 Feb 2011
    9.3
    Critical

    CVE-2011-0978

    Last Modified: 30 Apr 2011

    Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via vectors related to an axis properties record, and improper incrementing of an array index, aka "Excel Array Indexing Vulnerability."

    Source:webDEViL
    Published:10 Feb 2011
    6.8
    Medium

    CVE-2011-0966

    Last Modified: 14 Jan 2015

    Directory traversal vulnerability in cwhp/auditLog.do in the Homepage Auditing component in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, aka Bug ID CSCto35577.

    Source:Sense of Security
    Published:20 May 2011
    4.3
    Medium

    CVE-2011-0962

    Last Modified: 14 Jan 2015

    Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag parameter, aka Bug ID CSCto12712.

    Source:Sense of Security
    Published:20 May 2011
    4.3
    Medium

    CVE-2011-0961

    Last Modified: 14 Jan 2015

    Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the device parameter, aka Bug ID CSCto12704.

    Source:Sense of Security
    Published:20 May 2011
    7.5
    High

    CVE-2011-0960

    Last Modified: 18 May 2011

    Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to execute arbitrary SQL commands via (1) the CCMs parameter to iptm/PRTestCreation.do or (2) the ccm parameter to iptm/TelePresenceReportAction.do, aka Bug ID CSCtn61716.

    Source:Sense of Security
    Published:20 May 2011
    4.3
    Medium

    CVE-2011-0959

    Last Modified: 12 Jan 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to inject arbitrary web script or HTML via (1) the extn parameter to iptm/advancedfind.do, (2) the deviceInstanceName parameter to iptm/ddv.do, the (3) cmd or (4) group parameter to iptm/eventmon, the (5) clusterName or (6) deviceName parameter to iptm/faultmon/ui/dojo/Main/eventmon_wrapper.jsp, or the (7) ccmName or (8) clusterName parameter to iptm/logicalTopo.do, aka Bug ID CSCtn61716.

    Source:Sense of Security
    Published:20 May 2011
    10
    Critical

    CVE-2011-0923

    Last Modified: 5 Aug 2011

    The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."

    Source:Adrian Puente Z.
    Published:9 Feb 2011
    10
    Critical

    CVE-2011-0922

    Last Modified: 2 Aug 2013

    The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that references a UNC share pathname.

    Source:Ben Turner
    Published:9 Feb 2011
    9.3
    Critical

    CVE-2011-0920

    Last Modified: 30 Nov 2011

    The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and execute arbitrary code via unspecified vectors, aka SPR PRAD89WGRS.

    Source:Alexey Sintsov
    Published:8 Feb 2011
    10
    Critical

    CVE-2011-0917

    Last Modified: 18 Feb 2011

    Buffer overflow in nLDAP.exe in IBM Lotus Domino allows remote attackers to execute arbitrary code via a long string in an LDAP Bind operation, aka SPR KLYH87LMVX.

    Source:Francis Provencher
    Published:8 Feb 2011
    6.8
    Medium

    CVE-2011-0903

    Last Modified: 27 Jan 2011

    Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitrary files and possibly have other unspecified impact via a .. (dot dot) in the (1) awcm_theme or (2) awcm_lang cookie to (a) index.php or (b) header.php.

    Source:Cucura
    Published:7 Feb 2011
    6.9
    Medium

    CVE-2011-0902

    Last Modified: 25 Jan 2011

    Multiple untrusted search path vulnerabilities in the Java Service in Sun Microsystems SunScreen Firewall on SunOS 5.9 allow local users to execute arbitrary code via a modified (1) PATH or (2) LD_LIBRARY_PATH environment variable.

    Source:kingcope
    Published:7 Feb 2011
    6.8
    Medium

    CVE-2011-0901

    Last Modified: 2 Feb 2011

    Multiple stack-based buffer overflows in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions, allow user-assisted remote attackers to execute arbitrary code via a .RDP file with a long (1) username, (2) password, or (3) domain argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:D3V!L FUCKER
    Published:2 Feb 2011
    6.8
    Medium

    CVE-2011-0900

    Last Modified: 2 Feb 2011

    Stack-based buffer overflow in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a .RDP file with a long hostname argument.

    Source:D3V!L FUCKER
    Published:2 Feb 2011
    4.3
    Medium

    CVE-2011-0887

    Last Modified: 6 Feb 2011

    The web management portal on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware before 1.4.0.49.2 uses predictable session IDs based on time values, which makes it easier for remote attackers to hijack sessions via a brute-force attack on the userid cookie.

    Source:Trustwave's SpiderLabs
    Published:8 Feb 2011
    6.8
    Medium

    CVE-2011-0886

    Last Modified: 6 Feb 2011

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware before 1.4.0.49.2 allow remote attackers to (1) hijack the intranet connectivity of arbitrary users for requests that perform a login via goform/login, or hijack the authentication of administrators for requests that (2) enable external logins via an mso_remote_enable action to goform/RemoteRange or (3) change DNS settings via a manual_dns_enable action to goform/Basic.

    Source:Trustwave's SpiderLabs
    Published:8 Feb 2011
    10
    Critical

    CVE-2011-0885

    Last Modified: 6 Feb 2011

    A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default password of D0nt4g3tme for the mso account, which makes it easier for remote attackers to obtain administrative access via the (1) web interface or (2) TELNET interface.

    Source:Trustwave's SpiderLabs
    Published:8 Feb 2011
    3.5
    Low

    CVE-2011-0836

    Last Modified: 28 Dec 2014

    Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote authenticated users to affect integrity, related to Web Runtime SEC.

    Source:Juan Manuel Garcia
    Published:20 Apr 2011
    10
    Critical

    CVE-2011-0807

    Last Modified: 5 Aug 2011

    Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Application Server 9.1, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Administration.

    Source:Metasploit
    Published:20 Apr 2011
    4.3
    Medium

    CVE-2011-0773

    Last Modified: 16 Nov 2014

    Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the image parameter.

    Source:AutoSec Tools
    Published:4 Feb 2011
    4.3
    Medium

    CVE-2011-0772

    Last Modified: 17 Nov 2014

    Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow remote attackers to inject arbitrary web script or HTML via the (1) color parameter to includes/blogroll.php or (2) src parameter to includes/timwrapper.php.

    Source:High-Tech Bridge SA
    Published:4 Feb 2011
    4
    Medium

    CVE-2011-0762

    Last Modified: 7 Dec 2016

    The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.

    Source:Maksymilian Arciemowicz
    Published:1 Mar 2011
    5
    Medium

    CVE-2011-0761

    Last Modified: 8 Jan 2015

    Perl 5.10.x allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an ability to inject arguments into a (1) getpeername, (2) readdir, (3) closedir, (4) getsockname, (5) rewinddir, (6) tell, or (7) telldir function call.

    Source:Jonathan Brossard
    Published:3 May 2011