Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 390 981

Количество 390 981

nvd логотип

CVE-2011-1086

больше 6 лет назад

Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitrary web script or HTML via the device parameter.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2011-1085

больше 6 лет назад

CSRF vulnerability in Smoothwall Express 3.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2011-1084

больше 6 лет назад

A cross-site scripting (XSS) vulnerability in Smoothwall Express 3.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2011-1083

больше 15 лет назад

The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2011-1082

больше 15 лет назад

fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2011-1081

больше 15 лет назад

modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (aka MODRDN operation) that contains an empty value for the OldDN field.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2011-1080

около 14 лет назад

The do_replace function in net/bridge/netfilter/ebtables.c in the Linux kernel before 2.6.39 does not ensure that a certain name field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability to replace a table, and then reading a modprobe command line.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2011-1079

около 14 лет назад

The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.

CVSS2: 5.4
EPSS: Низкий
nvd логотип

CVE-2011-1078

около 14 лет назад

The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via the SCO_CONNINFO option.

CVSS2: 1.9
EPSS: Низкий
nvd логотип

CVE-2011-1077

больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-1076

почти 15 лет назад

net/dns_resolver/dns_key.c in the Linux kernel before 2.6.38 allows remote DNS servers to cause a denial of service (NULL pointer dereference and OOPS) by not providing a valid response to a DNS query, as demonstrated by an erroneous grand.centrall.org query, which triggers improper handling of error data within a DNS resolver key.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2011-1075

почти 5 лет назад

FreeBSD's crontab calculates the MD5 sum of the previous and new cronjob to determine if any changes have been made before copying the new version in. In particular, it uses the MD5File() function, which takes a pathname as an argument, and is called with euid 0. A race condition in this process may lead to an arbitrary MD5 comparison regardless of the read permissions.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2011-1074

больше 15 лет назад

crontab.c in crontab in FreeBSD allows local users to determine the existence of arbitrary directories via a command-line argument composed of a directory name concatenated with a directory traversal sequence that leads to the /etc/crontab pathname.

CVSS2: 1.9
EPSS: Низкий
nvd логотип

CVE-2011-1073

больше 15 лет назад

crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum comparisons on arbitrary pairs of files via two symlink attacks on /tmp/crontab.XXXXXXXXXX temporary files.

CVSS2: 1.9
EPSS: Низкий
nvd логотип

CVE-2011-1072

больше 15 лет назад

The installer in PEAR before 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories, a different vulnerability than CVE-2007-2519.

CVSS2: 3.3
EPSS: Низкий
nvd логотип

CVE-2011-1071

больше 15 лет назад

The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2011-1070

почти 7 лет назад

v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mode and potentially other consequences.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2011-1069

больше 6 лет назад

PHPShop through 0.8.1 has XSS.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2011-1068

больше 15 лет назад

Microsoft Windows Azure Software Development Kit (SDK) 1.3.x before 1.3.20121.1237, when Full IIS and a Web Role are used with an ASP.NET application, does not properly support the use of cookies for maintaining state, which allows remote attackers to obtain potentially sensitive information by reading an encrypted cookie and performing unspecified other steps.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2011-1067

больше 15 лет назад

slapd (aka ns-slapd) in 389 Directory Server before 1.2.8.a2 does not properly manage the c_timelimit field of the connection table element, which allows remote attackers to cause a denial of service (daemon outage) via Simple Paged Results connections, as demonstrated by using multiple processes to replay TCP sessions, a different vulnerability than CVE-2011-0019.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-1086

Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitrary web script or HTML via the device parameter.

CVSS3: 6.1
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-1085

CSRF vulnerability in Smoothwall Express 3.

CVSS3: 8.8
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-1084

A cross-site scripting (XSS) vulnerability in Smoothwall Express 3.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-1083

The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.

CVSS2: 4.9
1%
Низкий
больше 15 лет назад
nvd логотип
CVE-2011-1082

fs/eventpoll.c in the Linux kernel before 2.6.38 places epoll file descriptors within other epoll data structures without properly checking for (1) closed loops or (2) deep chains, which allows local users to cause a denial of service (deadlock or stack memory consumption) via a crafted application that makes epoll_create and epoll_ctl system calls.

CVSS2: 4.9
1%
Низкий
больше 15 лет назад
nvd логотип
CVE-2011-1081

modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (aka MODRDN operation) that contains an empty value for the OldDN field.

CVSS2: 5
14%
Средний
больше 15 лет назад
nvd логотип
CVE-2011-1080

The do_replace function in net/bridge/netfilter/ebtables.c in the Linux kernel before 2.6.39 does not ensure that a certain name field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability to replace a table, and then reading a modprobe command line.

CVSS2: 2.1
0%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-1079

The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, or cause a denial of service (BUG and system crash), via a BNEPCONNADD command.

CVSS2: 5.4
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-1078

The sco_sock_getsockopt_old function in net/bluetooth/sco.c in the Linux kernel before 2.6.39 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via the SCO_CONNINFO option.

CVSS2: 1.9
0%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-1077

Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
7%
Низкий
больше 15 лет назад
nvd логотип
CVE-2011-1076

net/dns_resolver/dns_key.c in the Linux kernel before 2.6.38 allows remote DNS servers to cause a denial of service (NULL pointer dereference and OOPS) by not providing a valid response to a DNS query, as demonstrated by an erroneous grand.centrall.org query, which triggers improper handling of error data within a DNS resolver key.

CVSS2: 4.9
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-1075

FreeBSD's crontab calculates the MD5 sum of the previous and new cronjob to determine if any changes have been made before copying the new version in. In particular, it uses the MD5File() function, which takes a pathname as an argument, and is called with euid 0. A race condition in this process may lead to an arbitrary MD5 comparison regardless of the read permissions.

CVSS3: 3.7
1%
Низкий
почти 5 лет назад
nvd логотип
CVE-2011-1074

crontab.c in crontab in FreeBSD allows local users to determine the existence of arbitrary directories via a command-line argument composed of a directory name concatenated with a directory traversal sequence that leads to the /etc/crontab pathname.

CVSS2: 1.9
1%
Низкий
больше 15 лет назад
nvd логотип
CVE-2011-1073

crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum comparisons on arbitrary pairs of files via two symlink attacks on /tmp/crontab.XXXXXXXXXX temporary files.

CVSS2: 1.9
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2011-1072

The installer in PEAR before 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories, a different vulnerability than CVE-2007-2519.

CVSS2: 3.3
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2011-1071

The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.

CVSS2: 5.1
14%
Средний
больше 15 лет назад
nvd логотип
CVE-2011-1070

v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mode and potentially other consequences.

CVSS3: 7.8
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2011-1069

PHPShop through 0.8.1 has XSS.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-1068

Microsoft Windows Azure Software Development Kit (SDK) 1.3.x before 1.3.20121.1237, when Full IIS and a Web Role are used with an ASP.NET application, does not properly support the use of cookies for maintaining state, which allows remote attackers to obtain potentially sensitive information by reading an encrypted cookie and performing unspecified other steps.

CVSS2: 2.6
10%
Низкий
больше 15 лет назад
nvd логотип
CVE-2011-1067

slapd (aka ns-slapd) in 389 Directory Server before 1.2.8.a2 does not properly manage the c_timelimit field of the connection table element, which allows remote attackers to cause a denial of service (daemon outage) via Simple Paged Results connections, as demonstrated by using multiple processes to replay TCP sessions, a different vulnerability than CVE-2011-0019.

CVSS2: 5
1%
Низкий
больше 15 лет назад

Уязвимостей на страницу