Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-1842 | 1 Ubuntu | 1 Language-selector | 2017-08-16 | 7.2 HIGH | N/A |
dbus_backend/lsd.py in the D-Bus backend in language-selector before 0.6.7 does not validate the arguments to the (1) SetSystemDefaultLangEnv and (2) SetSystemDefaultLanguageEnv functions, which allows local users to gain privileges via shell metacharacters in a string argument, a different vulnerability than CVE-2011-0729. | |||||
CVE-2011-1857 | 1 Hp | 2 Service Center, Service Manager | 2017-08-16 | 8.2 HIGH | N/A |
Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote authenticated users to bypass intended access restrictions via unknown vectors. | |||||
CVE-2011-1858 | 1 Hp | 2 Service Center, Service Manager | 2017-08-16 | 4.3 MEDIUM | N/A |
Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows local users to bypass intended access restrictions via unknown vectors. | |||||
CVE-2011-1859 | 1 Hp | 2 Service Center, Service Manager | 2017-08-16 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to obtain sensitive information via unknown vectors. | |||||
CVE-2011-1860 | 1 Hp | 2 Service Center, Service Manager | 2017-08-16 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to capture HTTP session credentials via unknown vectors. | |||||
CVE-2011-1861 | 1 Hp | 2 Service Center, Service Manager | 2017-08-16 | 8.3 HIGH | N/A |
Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to modify data or obtain sensitive information via unknown vectors. | |||||
CVE-2011-1862 | 1 Hp | 2 Service Center, Service Manager | 2017-08-16 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2011-1863 | 1 Hp | 2 Service Center, Service Manager | 2017-08-16 | 7.5 HIGH | N/A |
HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allow remote authenticated users to conduct unspecified script injection attacks via unknown vectors. | |||||
CVE-2011-1864 | 1 Hp | 1 Openview Storage Data Protector | 2017-08-16 | 9.3 HIGH | N/A |
Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to execute arbitrary code via unknown vectors. | |||||
CVE-2011-1865 | 1 Hp | 1 Openview Storage Data Protector | 2017-08-16 | 10.0 HIGH | N/A |
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to execute arbitrary code via a request containing crafted parameters. | |||||
CVE-2011-1908 | 1 Foxitsoftware | 1 Foxit Reader | 2017-08-16 | 9.3 HIGH | N/A |
Integer overflow in the Type 1 font decoder in the FreeType engine in Foxit Reader before 4.0.0.0619 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font in a PDF document. | |||||
CVE-2011-1911 | 1 Jasperforge | 1 Jasperreports Server Community Project | 2017-08-16 | 6.8 MEDIUM | N/A |
JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach. | |||||
CVE-2011-1913 | 1 Mercator | 1 Sentinel | 2017-08-16 | 7.5 HIGH | N/A |
SQL injection vulnerability in the login form in the web interface in Mercator SENTINEL 2.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2011-1920 | 2 Ihji, Netbsd | 2 Pmake, Netbsd | 2017-08-16 | 3.3 LOW | N/A |
The make include files in NetBSD before 1.6.2, as used in pmake 1.111 and other products, allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_depend##### temporary file, related to (1) bsd.lib.mk and (2) bsd.prog.mk. | |||||
CVE-2011-1922 | 1 Nlnetlabs | 1 Unbound | 2017-08-16 | 4.3 MEDIUM | N/A |
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling. | |||||
CVE-2011-1925 | 1 Wouter Verhelst | 1 Nbd | 2017-08-16 | 5.0 MEDIUM | N/A |
nbd-server.c in Network Block Device (nbd-server) 2.9.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by causing a negotiation failure, as demonstrated by specifying a name for a non-existent export. | |||||
CVE-2011-1929 | 1 Dovecot | 1 Dovecot | 2017-08-16 | 5.0 MEDIUM | N/A |
lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message. | |||||
CVE-2011-1938 | 1 Php | 1 Php | 2017-08-16 | 7.5 HIGH | N/A |
Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket. | |||||
CVE-2011-1946 | 1 Hongli Lai | 1 Libgnomesu | 2017-08-16 | 7.2 HIGH | N/A |
gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid function, which allows local users to gain privileges by leveraging access to two unprivileged user accounts, and running many processes under one of these accounts. | |||||
CVE-2017-12880 | 2017-08-16 | N/A | N/A | ||
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11424. Reason: This candidate is a duplicate of CVE-2017-11424. Notes: All CVE users should reference CVE-2017-11424 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. |