4
    Medium

    CVE-2011-0418

    Last Modified: 5 Feb 2013

    The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

    Source:Maksymilian Arciemowicz
    Published:24 May 2011
    7.5
    High

    CVE-2011-0407

    Last Modified: 6 Jan 2011

    SQL injection vulnerability in the store function in _phenotype/system/class/PhenoTypeDataObject.class.php in Phenotype CMS 3.0 allows remote attackers to execute arbitrary SQL commands via a crafted URI, as demonstrated by Gallery/gal_id/1/image1,1.html. NOTE: some of these details are obtained from third party information.

    Source:High-Tech Bridge SA
    Published:11 Jan 2011
    10
    Critical

    CVE-2011-0406

    Last Modified: 9 Jan 2011

    Heap-based buffer overflow in HistorySvr.exe in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a long request to TCP port 777.

    Source:Dillon Beresford
    Published:11 Jan 2011
    6.8
    Medium

    CVE-2011-0405

    Last Modified: 5 Jan 2011

    Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the pgvaction parameter.

    Source:dun
    Published:11 Jan 2011
    7.5
    High

    CVE-2011-0404

    Last Modified: 25 Apr 2011

    Stack-based buffer overflow in NetSupport Manager Agent for Linux 11.00, for Solaris 9.50, and for Mac OS X 11.00 allows remote attackers to execute arbitrary code via a long control hostname to TCP port 5405, probably a different vulnerability than CVE-2007-5252.

    Source:Metasploit
    Published:11 Jan 2011
    9.3
    Critical

    CVE-2011-0403

    Last Modified: 5 Nov 2014

    Untrusted search path vulnerability in ImgBurn.exe in ImgBurn 2.4.0.0, 2.5.4.0, and other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a CUE file.

    Source:d3c0der
    Published:11 Jan 2011
    10
    Critical

    CVE-2011-0364

    Last Modified: 12 Apr 2011

    The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers to create arbitrary files and execute arbitrary code via unspecified parameters in a crafted st_upload request.

    Source:Gerry Eisenhaur
    Published:18 Feb 2011
    10
    Critical

    CVE-2011-0354

    Last Modified: 2 Feb 2011

    The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an unspecified login method.

    Source:Cisco Security
    Published:3 Feb 2011
    9.3
    Critical

    CVE-2011-0340

    Last Modified: 20 Dec 2012

    Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.

    Source:Metasploit
    Published:4 May 2011
    10
    Critical

    CVE-2011-0285

    Last Modified: 25 Dec 2014

    The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.

    Source:Felipe Ortega
    Published:8 Apr 2011
    10
    Critical

    CVE-2011-0276

    Last Modified: 16 Mar 2011

    HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attackers to execute arbitrary code via the doPost method in the com.trinagy.servlet.HelpManagerServlet class.

    Source:Metasploit
    Published:2 Feb 2011
    10
    Critical

    CVE-2011-0267

    Last Modified: 24 Mar 2011

    Multiple buffer overflows in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attackers to execute arbitrary code via a long (1) schdParams or (2) nameParams parameter, a different vulnerability than CVE-2011-0266.

    Source:Metasploit
    Published:13 Jan 2011
    10
    Critical

    CVE-2011-0266

    Last Modified: 23 Mar 2011

    Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long nameParams parameter, a different vulnerability than CVE-2011-0267.2.

    Source:Metasploit
    Published:13 Jan 2011
    9.3
    Critical

    CVE-2011-0257

    Last Modified: 4 Sept 2011

    Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PnSize opcode in a PICT file that triggers a stack-based buffer overflow.

    Source:Metasploit
    Published:15 Aug 2011
    7.5
    High

    CVE-2011-0228

    Last Modified: 11 Apr 2025

    The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which allows man-in-the-middle attackers to spoof an SSL server by using a non-CA certificate to sign a certificate for an arbitrary domain.

    Published:29 Aug 2011
    9.3
    Critical

    CVE-2011-0222

    Last Modified: 25 Jul 2011

    WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.

    Source:Nikita Tarakanov
    Published:21 Jul 2011
    7.2
    High

    CVE-2011-0182

    Last Modified: 4 Oct 2017

    The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privileges via vectors involving the creation of a call gate entry.

    Source:hkpco
    Published:23 Mar 2011
    2.1
    Low

    CVE-2011-0180

    Last Modified: 8 Dec 2014

    Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) HFS+J files via a crafted F_READBOOTSTRAP ioctl call.

    Source:Dan Rosenberg
    Published:23 Mar 2011
    4.3
    Medium

    CVE-2011-0167

    Last Modified: 3 Dec 2014

    The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.

    Source:Aaron Sigel
    Published:11 Mar 2011
    Low

    CVE-2011-0108

    Last Modified: 25 Aug 2010

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Source:Beenu Arora
    Published:11 May 2017
    9.3
    Critical

    CVE-2011-0105

    Last Modified: 7 Nov 2011

    Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."

    Source:Metasploit
    Published:13 Apr 2011
    9.3
    Critical

    CVE-2011-0104

    Last Modified: 27 Dec 2014

    Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."

    Source:Rodrigo Rubira Branco
    Published:13 Apr 2011
    6.1
    Medium

    CVE-2011-0096

    Last Modified: 29 Jan 2011

    The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."

    Source:80vul
    Published:31 Jan 2011
    10
    Critical

    CVE-2011-0073

    Last Modified: 20 Jun 2011

    Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."

    Source:Abysssec
    Published:28 Apr 2011
    10
    Critical

    CVE-2011-0065

    Last Modified: 1 Apr 2017

    Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel.

    Source:Metasploit
    Published:28 Apr 2011
    5
    Medium

    CVE-2011-0063

    Last Modified: 3 Feb 2011

    The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and read arbitrary files via a ./.../ sequence in the "extra" parameter to the help command, which causes the regular expression to produce .. (dot dot) sequences. NOTE: this vulnerability is due to an incomplete fix for CVE-2011-0049.

    Source:Michael Brooks
    Published:15 Mar 2011
    5
    Medium

    CVE-2011-0049

    Last Modified: 3 Feb 2011

    Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the help command, as demonstrated using (1) a crafted email and (2) cgi-bin/mj_wwwusr in the web interface.

    Source:Michael Brooks
    Published:4 Feb 2011
    7.2
    High

    CVE-2011-0045

    Last Modified: 1 Mar 2011

    The Trace Events functionality in the kernel in Microsoft Windows XP SP3 does not properly perform type conversion, which causes integer truncation and insufficient memory allocation and triggers a buffer overflow, which allows local users to gain privileges via a crafted application, related to WmiTraceMessageVa, aka "Windows Kernel Integer Truncation Vulnerability."

    Source:Nikita Tarakanov
    Published:9 Feb 2011
    9.3
    Critical

    CVE-2011-0041

    Last Modified: 24 Jul 2011

    Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF image, aka "GDI+ Integer Overflow Vulnerability."

    Source:Abysssec
    Published:13 Apr 2011
    9.3
    Critical

    CVE-2011-0027

    Last Modified: 15 Nov 2017

    Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.

    Source:Peter Vreugdenhil
    Published:12 Jan 2011
    7.6
    High

    CVE-2011-0020

    Last Modified: 14 Nov 2014

    Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.

    Source:Dan Rosenberg
    Published:18 Jan 2011
    9
    Critical

    CVE-2011-0018

    Last Modified: 31 Jan 2011

    The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execute arbitrary commands via the (1) To or (2) From e-mail address in an OMP request to the Greenbone Security Assistant (GSA).

    Source:Tim Brown
    Published:28 Jan 2011
    4.3
    Medium

    CVE-2011-0005

    Last Modified: 6 Nov 2014

    Cross-site scripting (XSS) vulnerability in the com_search module for Joomla! 1.0.x through 1.0.15 allows remote attackers to inject arbitrary web script or HTML via the ordering parameter to index.php.

    Source:Aung Khant
    Published:11 Jan 2011
    10
    Critical

    CVE-2010-5324

    Last Modified: 1 Apr 2017

    Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to execute arbitrary code via a zenworks-fileupload request with a crafted directory name in the type parameter, in conjunction with a WAR filename in the filename parameter and WAR content in the POST data, a different vulnerability than CVE-2010-5323.

    Source:Metasploit
    Published:7 Jun 2015
    10
    Critical

    CVE-2010-5323

    Last Modified: 1 Apr 2017

    Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to execute arbitrary code via a crafted WAR pathname in the filename parameter in conjunction with WAR content in the POST data, a different vulnerability than CVE-2010-5324.

    Source:Metasploit
    Published:7 Jun 2015
    4.3
    Medium

    CVE-2010-5322

    Last Modified: 28 Nov 2016

    Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to index.php.

    Source:Steffen Rösemann
    Published:11 Mar 2015
    4.3
    Medium

    CVE-2010-5318

    Last Modified: 2 Nov 2016

    The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator's password by specifying the administrator's e-mail address in the email parameter.

    Source:High-Tech Bridge SA
    Published:3 Jan 2015
    7.5
    High

    CVE-2010-5317

    Last Modified: 2 Nov 2016

    Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute arbitrary SQL commands via (1) the file_name parameter in an attachment action, (2) the post parameter in a show_comment action, (3) the sys-name parameter in an rssfeed action, or (4) the sys-name parameter in a view action.

    Source:High-Tech Bridge SA
    Published:3 Jan 2015
    6.8
    Medium

    CVE-2010-5315

    Last Modified: 15 Dec 2010

    Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita before 3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create categories via a data array to news/saveCategories or (2) modify credentials via a data array to admin/saveUser.

    Source:High-Tech Bridge SA
    Published:3 Jan 2015
    7.5
    High

    CVE-2010-5301

    Last Modified: 29 Dec 2010

    Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a HEAD request.

    Source:TheLeader
    Published:13 Jun 2014
    6.8
    Medium

    CVE-2010-5300

    Last Modified: 17 Apr 2014

    Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name in a zip archive.

    Source:motaz reda
    Published:11 Jun 2014
    6.8
    Medium

    CVE-2010-5299

    Last Modified: 14 Mar 2014

    Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl file. NOTE: it has been reported that the overflow is in the lpFileName parameter of the CreateFileA function, but the overflow is probably caused by a separate, unnamed function.

    Source:Necmettin COSKUN
    Published:23 May 2014
    7.5
    High

    CVE-2010-5289

    Last Modified: 5 Sept 2010

    Buffer overflow in the Authenticate method in the INCREDISPOOLERLib.Pop ActiveX control in ImSpoolU.dll in IncrediMail 2.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long string in the first argument.

    Source:d3b4g
    Published:25 Aug 2013
    7.5
    High

    CVE-2010-5287

    Last Modified: 22 Jun 2010

    SQL injection vulnerability in default.php in Cornerstone Technologies webConductor allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Th3 RDX
    Published:31 Jan 2013
    10
    Critical

    CVE-2010-5286

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Source:jos_ali_joe
    Published:26 Nov 2012
    6.8
    Medium

    CVE-2010-5285

    Last Modified: 12 Oct 2010

    Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrators for requests that add administrative users via the edituser action.

    Source:Anatolia Security
    Published:26 Nov 2012
    4.3
    Medium

    CVE-2010-5284

    Last Modified: 12 Oct 2010

    Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User parameter in the edit user profile feature to manageuser.php, (2) y parameter in a newcal action to manageajax.php, and the (3) pic parameter to thumb.php.

    Source:Anatolia Security
    Published:26 Nov 2012
    6.8
    Medium

    CVE-2010-5281

    Last Modified: 17 Sept 2011

    Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. NOTE: some of these details are obtained from third party information.

    Source:LiquidWorm
    Published:26 Nov 2012
    7.5
    High

    CVE-2010-5280

    Last Modified: 15 Dec 2016

    Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabname parameter in a userProfile action to index.php. NOTE: this can be leveraged to execute arbitrary code by using the file upload feature.

    Source:Delf Tonder
    Published:26 Nov 2012
    4.3
    Medium

    CVE-2010-5278

    Last Modified: 26 Sept 2014

    Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter. NOTE: some of these details are obtained from third party information.

    Source:John Leitch
    Published:7 Oct 2012