Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-3223 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 6.8 MEDIUM | N/A |
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLIC movie file. | |||||
CVE-2011-3224 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 2.6 LOW | N/A |
The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to App Store help information, which allows man-in-the-middle attackers to execute arbitrary code by spoofing the http server. | |||||
CVE-2011-3225 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 5.0 MEDIUM | N/A |
The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-restricted folder, which allows remote attackers to bypass intended browsing restrictions by leveraging access to the nobody account. | |||||
CVE-2011-3226 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 6.8 MEDIUM | N/A |
Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypass the password requirement by leveraging lack of an AuthenticationAuthority attribute for a user account. | |||||
CVE-2011-3227 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 6.8 MEDIUM | N/A |
libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message. | |||||
CVE-2011-3228 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 6.8 MEDIUM | N/A |
QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file. | |||||
CVE-2011-2308 | 1 Oracle | 1 E-business Suite | 2012-01-13 | 4.3 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Online Help. | |||||
CVE-2011-2404 | 1 Hp | 1 Easy Printer Care Software | 2012-01-13 | 7.5 HIGH | N/A |
A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via unspecified vectors, a different vulnerability than CVE-2011-4786 and CVE-2011-4787. | |||||
CVE-2011-0185 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 4.4 MEDIUM | N/A |
Format string vulnerability in the debug-logging feature in Application Firewall in Apple Mac OS X before 10.7.2 allows local users to gain privileges via a crafted name of an executable file. | |||||
CVE-2011-0224 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 6.8 MEDIUM | N/A |
CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QuickTime movie file. | |||||
CVE-2011-0229 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 6.8 MEDIUM | N/A |
Apple Type Services (ATS) in Apple Mac OS X through 10.6.8 does not properly handle embedded Type 1 fonts, which allows remote attackers to execute arbitrary code via a crafted document that triggers an out-of-bounds memory access. | |||||
CVE-2011-0230 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 7.5 HIGH | N/A |
Buffer overflow in the ATSFontDeactivate API in Apple Type Services (ATS) in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. | |||||
CVE-2011-0231 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 5.0 MEDIUM | N/A |
CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to track users via a cookie, related to a "synchronization issue." | |||||
CVE-2011-0260 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-01-13 | 4.6 MEDIUM | N/A |
The CoreProcesses component in Apple Mac OS X 10.7 before 10.7.2 does not prevent a system window from receiving keystrokes in the locked-screen state, which might allow physically proximate attackers to bypass intended access restrictions by typing into this window. | |||||
CVE-2011-5059 | 1 Finaldraft | 1 Finaldraft | 2012-01-12 | 10.0 HIGH | N/A |
Stack-based buffer overflow in Final Draft 8 before 8.02 allows remote attackers to execute arbitrary code via a crafted SmartType element, a different vulnerability than CVE-2011-5002. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2011-3990 | 1 Pukiwiki | 1 Pukiwiki Plus\! | 2012-01-11 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in plugin/comment.inc.php in PukiWiki Plus! 1.4.7plus-u2-i18n and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2011-4037 | 1 Sielcosistemi | 2 Winlog Lite, Winlog Pro | 2012-01-11 | 9.3 HIGH | N/A |
Buffer overflow in Sielco Sistemi Winlog PRO before 2.07.09 and Winlog Lite before 2.07.09 allows user-assisted remote attackers to execute arbitrary code via invalid data in unspecified fields of a project file. | |||||
CVE-2011-4453 | 1 Pmwiki | 1 Pmwiki | 2012-01-11 | 7.5 HIGH | N/A |
The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive, leading to unintended use of the PHP create_function function. | |||||
CVE-2011-2292 | 1 Oracle | 1 Solaris | 2012-01-11 | 2.4 LOW | N/A |
Unspecified vulnerability in Oracle Solaris 9 and 11 Express allows local users to affect confidentiality and integrity via unknown vectors related to xscreensaver. | |||||
CVE-2011-2309 | 1 Oracle | 1 Industry Applications | 2012-01-11 | 4.3 MEDIUM | N/A |
Unspecified vulnerability in the Health Sciences - Oracle Clinical, Remote Data Capture component in Oracle Industry Applications 4.6 and 4.6.2 allows remote attackers to affect integrity, related to RDC Help. |