Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-2778 | 1 Tor | 1 Tor | 2012-01-18 | 7.6 HIGH | N/A |
Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by (1) establishing a SOCKS connection to SocksPort or (2) leveraging a SOCKS proxy configuration. | |||||
CVE-2011-1772 | 2 Apache, Opensymphony | 3 Struts, Webwork, Xwork | 2012-01-18 | 2.6 LOW | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element. | |||||
CVE-2011-2176 | 1 Gnome | 1 Networkmanager | 2012-01-18 | 2.1 LOW | N/A |
GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors. | |||||
CVE-2010-2640 | 1 Redhat | 1 Evince | 2012-01-18 | 7.6 HIGH | N/A |
Array index error in the PK font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer. | |||||
CVE-2010-2641 | 1 Redhat | 1 Evince | 2012-01-18 | 7.6 HIGH | N/A |
Array index error in the VF font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer. | |||||
CVE-2010-2643 | 1 Redhat | 1 Evince | 2012-01-18 | 7.6 HIGH | N/A |
Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer. | |||||
CVE-2009-5064 | 1 Gnu | 1 Glibc | 2012-01-18 | 6.9 MEDIUM | N/A |
** DISPUTED ** ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states "This is just nonsense. There are a gazillion other ways to introduce code if people are downloading arbitrary binaries and install them in appropriate directories or set LD_LIBRARY_PATH etc." | |||||
CVE-2009-2702 | 1 Kde | 1 Kdelibs | 2012-01-18 | 7.5 HIGH | N/A |
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. | |||||
CVE-2011-2170 | 1 Google | 1 Chrome Os | 2012-01-17 | 4.4 MEDIUM | N/A |
Google Chrome OS before R12 0.12.433.38 Beta, when Guest mode is enabled, does not prevent changes on the about:flags page, which has unspecified impact and local attack vectors. | |||||
CVE-2011-2171 | 1 Google | 1 Chrome Os | 2012-01-17 | 10.0 HIGH | N/A |
Unspecified vulnerability in the dbugs package in Google Chrome OS before R12 0.12.433.38 Beta has unknown impact and attack vectors. | |||||
CVE-2011-4057 | 1 Wibu | 1 Codemeter Runtime | 2012-01-15 | 5.0 MEDIUM | N/A |
Wibu-Systems AG CodeMeter Runtime 4.30c, 4.10b, and possibly other versions before 4.40 allows remote attackers to cause a denial of service (CodeMeter.exe crash) via certain crafted packets to TCP port 22350. | |||||
CVE-2011-3213 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 7.6 HIGH | N/A |
The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection. | |||||
CVE-2011-3214 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 4.6 MEDIUM | N/A |
IOGraphics in Apple Mac OS X through 10.6.8 does not properly handle a locked-screen state in display sleep mode for an Apple Cinema Display, which allows physically proximate attackers to bypass the password requirement via unspecified vectors. | |||||
CVE-2011-3215 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 2.1 LOW | N/A |
The kernel in Apple Mac OS X before 10.7.2 does not properly prevent FireWire DMA in the absence of a login, which allows physically proximate attackers to bypass intended access restrictions and discover a password by making a DMA request in the (1) loginwindow, (2) boot, or (3) shutdown state. | |||||
CVE-2011-3216 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 2.1 LOW | N/A |
The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow local users to bypass intended permissions and delete files via an unlink system call. | |||||
CVE-2011-3217 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 6.8 MEDIUM | N/A |
MediaKit in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image. | |||||
CVE-2011-3218 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 2.6 LOW | N/A |
The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document. | |||||
CVE-2011-3220 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 4.3 MEDIUM | N/A |
QuickTime in Apple Mac OS X before 10.7.2 does not properly process URL data handlers in movie files, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file. | |||||
CVE-2011-3221 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 6.8 MEDIUM | N/A |
QuickTime in Apple Mac OS X before 10.7.2 does not properly handle the atom hierarchy in movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file. | |||||
CVE-2011-3222 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 6.8 MEDIUM | N/A |
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file. |