Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 393 962

Количество 393 962

nvd логотип

CVE-2011-5328

около 7 лет назад

The user-access-manager plugin before 1.2 for WordPress has CSRF.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2011-5327

около 7 лет назад

In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function could result in at least memory corruption.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2011-5326

больше 10 лет назад

imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-5325

около 9 лет назад

Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-5324

около 11 лет назад

The TeraRecon server, as used in GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions, has a password of (1) shared for the shared user and (2) scan for the scan user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-5323

около 11 лет назад

GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions has a password of A11enda1e for the sa SQL server user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-5322

около 11 лет назад

GE Healthcare Centricity Analytics Server 1.1 has a default password of (1) V0yag3r for the SQL Server sa user, (2) G3car3s for the analyst user, (3) G3car3s for the ccg user, (4) V0yag3r for the viewer user, and (5) geservice for the geservice user in the Webmin interface, which has unspecified impact and attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-5321

больше 10 лет назад

The tty_open function in drivers/tty/tty_io.c in the Linux kernel before 3.1.1 mishandles a driver-lookup failure, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted access to a device file under the /dev/pts directory.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2011-5320

почти 9 лет назад

scanf and related functions in glibc before 2.15 allow local users to cause a denial of service (segmentation fault) via a large string of 0s.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2011-5319

больше 11 лет назад

content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accelerometer data, which makes it easier for remote attackers to capture keystrokes via a crafted web site that listens for ondevicemotion events, a different vulnerability than CVE-2015-1231.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-5318

больше 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in diafan.CMS before 5.1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify articles via a save_post action to admin/news/saveNEWS_ID/, (2) modify settings via a save_post action to admin/site/save2/, or (3) modify credentials via a save_post action to admin/usersite/save2/.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-5317

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in editText.php in WonderCMS before 0.4 allows remote attackers to inject arbitrary web script or HTML via the content parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-5316

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in admin/index.php in Cambio 0.5a nightly r37 allows remote attackers to hijack the authentication of administrators for requests that modify credentials via a user save action.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-5315

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in admin/index.php in whCMS 0.115 alpha allows remote attackers to hijack the authentication of administrators for requests that modify credentials via a user save action.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-5314

больше 11 лет назад

templates/default/index.php in Redaxscript 0.3.2 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-5313

больше 11 лет назад

Multiple SQL injection vulnerabilities in includes/password.php in Redaxscript 0.3.2 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) password parameter to the password_reset program.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-5312

больше 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Gollos 2.8 allow remote attackers to inject arbitrary web script or HTML via the returnurl parameter to (1) register.aspx, (2) publication/info.aspx, or (3) user/add.aspx, or (4) the q parameter to product/list.aspx.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-5311

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in pages.php in Wikipad 1.6.0 allows remote attackers to hijack the authentication of administrators for requests that modify pages via the data[text] parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-5310

больше 11 лет назад

Directory traversal vulnerability in pages.php in Wikipad 1.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-5309

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in pages.php in Wikipad 1.6.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-5328

The user-access-manager plugin before 1.2 for WordPress has CSRF.

CVSS3: 8.8
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2011-5327

In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function could result in at least memory corruption.

CVSS3: 9.8
4%
Низкий
около 7 лет назад
nvd логотип
CVE-2011-5326

imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse.

CVSS3: 7.5
3%
Низкий
больше 10 лет назад
nvd логотип
CVE-2011-5325

Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.

CVSS3: 7.5
7%
Низкий
около 9 лет назад
nvd логотип
CVE-2011-5324

The TeraRecon server, as used in GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions, has a password of (1) shared for the shared user and (2) scan for the scan user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

CVSS2: 10
2%
Низкий
около 11 лет назад
nvd логотип
CVE-2011-5323

GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions has a password of A11enda1e for the sa SQL server user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

CVSS2: 10
2%
Низкий
около 11 лет назад
nvd логотип
CVE-2011-5322

GE Healthcare Centricity Analytics Server 1.1 has a default password of (1) V0yag3r for the SQL Server sa user, (2) G3car3s for the analyst user, (3) G3car3s for the ccg user, (4) V0yag3r for the viewer user, and (5) geservice for the geservice user in the Webmin interface, which has unspecified impact and attack vectors.

CVSS2: 10
2%
Низкий
около 11 лет назад
nvd логотип
CVE-2011-5321

The tty_open function in drivers/tty/tty_io.c in the Linux kernel before 3.1.1 mishandles a driver-lookup failure, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted access to a device file under the /dev/pts directory.

CVSS3: 5.5
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2011-5320

scanf and related functions in glibc before 2.15 allow local users to cause a denial of service (segmentation fault) via a large string of 0s.

CVSS3: 6.2
0%
Низкий
почти 9 лет назад
nvd логотип
CVE-2011-5319

content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accelerometer data, which makes it easier for remote attackers to capture keystrokes via a crafted web site that listens for ondevicemotion events, a different vulnerability than CVE-2015-1231.

CVSS2: 5
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2011-5318

Multiple cross-site request forgery (CSRF) vulnerabilities in diafan.CMS before 5.1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify articles via a save_post action to admin/news/saveNEWS_ID/, (2) modify settings via a save_post action to admin/site/save2/, or (3) modify credentials via a save_post action to admin/usersite/save2/.

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2011-5317

Cross-site scripting (XSS) vulnerability in editText.php in WonderCMS before 0.4 allows remote attackers to inject arbitrary web script or HTML via the content parameter.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2011-5316

Cross-site request forgery (CSRF) vulnerability in admin/index.php in Cambio 0.5a nightly r37 allows remote attackers to hijack the authentication of administrators for requests that modify credentials via a user save action.

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2011-5315

Cross-site request forgery (CSRF) vulnerability in admin/index.php in whCMS 0.115 alpha allows remote attackers to hijack the authentication of administrators for requests that modify credentials via a user save action.

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2011-5314

templates/default/index.php in Redaxscript 0.3.2 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

CVSS2: 5
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2011-5313

Multiple SQL injection vulnerabilities in includes/password.php in Redaxscript 0.3.2 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) password parameter to the password_reset program.

CVSS2: 7.5
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2011-5312

Multiple cross-site scripting (XSS) vulnerabilities in Gollos 2.8 allow remote attackers to inject arbitrary web script or HTML via the returnurl parameter to (1) register.aspx, (2) publication/info.aspx, or (3) user/add.aspx, or (4) the q parameter to product/list.aspx.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2011-5311

Cross-site request forgery (CSRF) vulnerability in pages.php in Wikipad 1.6.0 allows remote attackers to hijack the authentication of administrators for requests that modify pages via the data[text] parameter.

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2011-5310

Directory traversal vulnerability in pages.php in Wikipad 1.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

CVSS2: 5
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2011-5309

Cross-site scripting (XSS) vulnerability in pages.php in Wikipad 1.6.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад

Уязвимостей на страницу