Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 796

Количество 63 796

ubuntu логотип

CVE-2011-4940

больше 13 лет назад

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2011-4939

почти 14 лет назад

The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2011-4931

больше 6 лет назад

gpw generates shorter passwords than required

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4930

почти 12 лет назад

Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string specifiers in (1) the reason for a hold for a job that uses an XML user log, (2) the filename of a file to be transferred, and possibly other unspecified vectors.

CVSS2: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2011-4929

больше 13 лет назад

Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.

CVSS2: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2011-4928

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine before 1.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4927

больше 13 лет назад

Unspecified vulnerability in the bazaar repository adapter in Redmine 1.0.x before 1.0.5 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2011-4925

около 14 лет назад

Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2011-4924

около 6 лет назад

Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2011-4923

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0, 3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the num parameter in a view action to index.cgi, related to the log file viewer, a different vulnerability than CVE-2011-3361.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4922

больше 13 лет назад

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents. It was discovered that libpurple versions prior to 2.7.10 do not properly clear certain data structures used in libpurple/cipher.c prior to freeing. An attacker could potentially extract partial information from memory regions freed by libpurple.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2011-4919

около 6 лет назад

mpack 1.6 has information disclosure via eavesdropping on mails sent by other users

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4917

почти 4 года назад

In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4916

больше 3 лет назад

Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4915

почти 6 лет назад

fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4914

больше 13 лет назад

The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a ROSE socket.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2011-4913

больше 13 лет назад

The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4905

около 14 лет назад

Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-4904

больше 6 лет назад

TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4903

больше 6 лет назад

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-4940

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.

CVSS2: 2.6
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4939

The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.

CVSS2: 6.4
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2011-4931

gpw generates shorter passwords than required

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2011-4930

Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string specifiers in (1) the reason for a hold for a job that uses an XML user log, (2) the filename of a file to be transferred, and possibly other unspecified vectors.

CVSS2: 4.4
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-4929

Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attackers to execute arbitrary commands via unknown vectors.

CVSS2: 7.5
74%
Высокий
больше 13 лет назад
ubuntu логотип
CVE-2011-4928

Cross-site scripting (XSS) vulnerability in the textile formatter in Redmine before 1.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4927

Unspecified vulnerability in the bazaar repository adapter in Redmine 1.0.x before 1.0.5 allows remote authenticated users to obtain sensitive information via unknown vectors.

CVSS2: 4
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4925

Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors.

CVSS2: 4.9
0%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-4924

Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104

CVSS3: 6.1
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2011-4923

Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0, 3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the num parameter in a view action to index.cgi, related to the log file viewer, a different vulnerability than CVE-2011-3361.

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2011-4922

cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents. It was discovered that libpurple versions prior to 2.7.10 do not properly clear certain data structures used in libpurple/cipher.c prior to freeing. An attacker could potentially extract partial information from memory regions freed by libpurple.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4919

mpack 1.6 has information disclosure via eavesdropping on mails sent by other users

CVSS3: 7.5
2%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2011-4917

In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2011-4916

Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2011-4915

fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.

CVSS3: 5.5
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2011-4914

The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a ROSE socket.

CVSS2: 6.4
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4913

The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.

CVSS2: 7.8
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4905

Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.

CVSS2: 5
10%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-4904

TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2011-4903

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function.

CVSS3: 6.1
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу