Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 686

Количество 63 686

ubuntu логотип

CVE-2011-4968

около 6 лет назад

nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4966

почти 13 лет назад

modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2011-4963

больше 13 лет назад

nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-4957

больше 13 лет назад

The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE library, which allows remote attackers to cause a denial of service (crash) via a comment with a crafted URL that triggers many recursive calls.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-4956

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4954

около 6 лет назад

cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4953

больше 11 лет назад

The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4952

около 6 лет назад

cobbler: Web interface lacks CSRF protection when using Django framework

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4945

больше 13 лет назад

PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentication.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2011-4944

больше 13 лет назад

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2011-4940

больше 13 лет назад

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2011-4939

почти 14 лет назад

The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2011-4931

больше 6 лет назад

gpw generates shorter passwords than required

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4930

почти 12 лет назад

Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string specifiers in (1) the reason for a hold for a job that uses an XML user log, (2) the filename of a file to be transferred, and possibly other unspecified vectors.

CVSS2: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2011-4929

больше 13 лет назад

Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.

CVSS2: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2011-4928

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine before 1.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4927

больше 13 лет назад

Unspecified vulnerability in the bazaar repository adapter in Redmine 1.0.x before 1.0.5 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2011-4925

около 14 лет назад

Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2011-4924

около 6 лет назад

Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2011-4923

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0, 3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the num parameter in a view action to index.cgi, related to the log file viewer, a different vulnerability than CVE-2011-3361.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-4968

nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)

CVSS3: 4.8
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2011-4966

modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.

CVSS2: 6
1%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2011-4963

nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.

CVSS2: 5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4957

The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before passing them to the PCRE library, which allows remote attackers to cause a denial of service (crash) via a comment with a crafted URL that triggers many recursive calls.

CVSS2: 5
2%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4956

Cross-site scripting (XSS) vulnerability in WordPress before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4954

cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE

CVSS3: 7.8
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2011-4953

The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet.

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2011-4952

cobbler: Web interface lacks CSRF protection when using Django framework

CVSS3: 8.8
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2011-4945

PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentication.

CVSS2: 6.9
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4944

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

CVSS2: 1.9
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4940

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.

CVSS2: 2.6
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4939

The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.

CVSS2: 6.4
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2011-4931

gpw generates shorter passwords than required

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2011-4930

Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string specifiers in (1) the reason for a hold for a job that uses an XML user log, (2) the filename of a file to be transferred, and possibly other unspecified vectors.

CVSS2: 4.4
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-4929

Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.

CVSS2: 7.5
74%
Высокий
больше 13 лет назад
ubuntu логотип
CVE-2011-4928

Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine before 1.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4927

Unspecified vulnerability in the bazaar repository adapter in Redmine 1.0.x before 1.0.5 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVSS2: 4
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4925

Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors.

CVSS2: 4.9
0%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-4924

Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104

CVSS3: 6.1
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2011-4923

Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0, 3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the num parameter in a view action to index.cgi, related to the log file viewer, a different vulnerability than CVE-2011-3361.

CVSS2: 4.3
1%
Низкий
почти 14 лет назад

Уязвимостей на страницу