Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 393 454

Количество 393 454

nvd логотип

CVE-2011-4128

почти 15 лет назад

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4127

около 14 лет назад

The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2011-4126

почти 5 лет назад

Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2011-4125

почти 5 лет назад

A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2011-4124

почти 5 лет назад

Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2011-4123

больше 14 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-3874. Reason: This candidate is a duplicate of CVE-2011-3874. Notes: All CVE users should reference CVE-2011-3874 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2011-4122

почти 15 лет назад

Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to kcheckpass.

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2011-4121

почти 7 лет назад

The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2011-4120

почти 7 лет назад

Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2011-4119

почти 5 лет назад

caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2011-4118

почти 15 лет назад

Mahara before 1.4.1, when MNet (aka the Moodle network feature) is used, allows remote authenticated users to gain privileges via a jump to an XMLRPC target.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2011-4117

больше 6 лет назад

The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-4116

больше 6 лет назад

_is_safe in the File::Temp module for Perl does not properly handle symlinks.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2011-4115

больше 6 лет назад

Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-4114

больше 14 лет назад

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

CVSS2: 3.3
EPSS: Низкий
nvd логотип

CVE-2011-4113

больше 14 лет назад

SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-4112

больше 14 лет назад

The net subsystem in the Linux kernel before 3.1 does not properly restrict use of the IFF_TX_SKB_SHARING flag, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability to access /proc/net/pktgen/pgctrl, and then using the pktgen package in conjunction with a bridge device for a VLAN interface.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2011-4111

больше 12 лет назад

Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-4110

больше 14 лет назад

The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2011-4109

больше 14 лет назад

Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an unspecified impact by triggering failure of a policy check.

CVSS2: 9.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-4128

Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-4127

The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.

CVSS2: 4.6
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-4126

Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.

CVSS3: 8.1
2%
Низкий
почти 5 лет назад
nvd логотип
CVE-2011-4125

A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.

CVSS3: 9.8
2%
Низкий
почти 5 лет назад
nvd логотип
CVE-2011-4124

Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.

CVSS3: 9.8
2%
Низкий
почти 5 лет назад
nvd логотип
CVE-2011-4123

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-3874. Reason: This candidate is a duplicate of CVE-2011-3874. Notes: All CVE users should reference CVE-2011-3874 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

больше 14 лет назад
nvd логотип
CVE-2011-4122

Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to kcheckpass.

CVSS2: 6.9
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-4121

The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.

CVSS3: 9.8
3%
Низкий
почти 7 лет назад
nvd логотип
CVE-2011-4120

Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.

CVSS3: 9.8
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2011-4119

caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.

CVSS3: 9.8
2%
Низкий
почти 5 лет назад
nvd логотип
CVE-2011-4118

Mahara before 1.4.1, when MNet (aka the Moodle network feature) is used, allows remote authenticated users to gain privileges via a jump to an XMLRPC target.

CVSS2: 6
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-4117

The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files.

CVSS3: 7.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-4116

_is_safe in the File::Temp module for Perl does not properly handle symlinks.

CVSS3: 3.3
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-4115

Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-4114

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

CVSS2: 3.3
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-4113

SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."

CVSS2: 7.5
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-4112

The net subsystem in the Linux kernel before 3.1 does not properly restrict use of the IFF_TX_SKB_SHARING flag, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability to access /proc/net/pktgen/pgctrl, and then using the pktgen package in conjunction with a bridge device for a VLAN interface.

CVSS3: 5.5
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-4111

Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.

CVSS2: 6.8
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2011-4110

The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."

CVSS2: 2.1
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-4109

Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an unspecified impact by triggering failure of a policy check.

CVSS2: 9.3
17%
Средний
больше 14 лет назад

Уязвимостей на страницу