Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 62 725

Количество 62 725

ubuntu логотип

CVE-2011-1439

больше 14 лет назад

Google Chrome before 11.0.696.57 on Linux does not properly isolate renderer processes, which has unspecified impact and remote attack vectors.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-1438

больше 14 лет назад

Google Chrome before 11.0.696.57 allows remote attackers to bypass the Same Origin Policy via vectors involving blobs.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-1437

больше 14 лет назад

Multiple integer overflows in Google Chrome before 11.0.696.57 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float rendering.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-1436

больше 14 лет назад

Google Chrome before 11.0.696.57 on Linux does not properly interact with the X Window System, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-1435

больше 14 лет назад

Google Chrome before 11.0.696.57 does not properly implement the tabs permission for extensions, which allows remote attackers to read local files via a crafted extension.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-1434

больше 14 лет назад

Google Chrome before 11.0.696.57 does not ensure thread safety during handling of MIME data, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-1433

почти 15 лет назад

The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the session data in the database, which makes it easier for context-dependent attackers to obtain sensitive information by reading the _UserLogin and _UserPW fields.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-1431

почти 15 лет назад

The STARTTLS implementation in qmail-smtpd.c in qmail-smtpd in the netqmail-1.06-tls patch for netqmail 1.06 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-1429

почти 15 лет назад

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-1428

почти 15 лет назад

Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL chat server via an arbitrary certificate, related to incorrect use of the GnuTLS API.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-1425

больше 14 лет назад

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2011-1416

почти 15 лет назад

The Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246 allows attackers to read the contents of memory locations via unknown vectors, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-1415

почти 15 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-1290. Reason: This candidate is a duplicate of CVE-2011-1290. Notes: All CVE users should reference CVE-2011-1290 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
ubuntu логотип

CVE-2011-1413

почти 15 лет назад

Google Chrome before 10.0.648.127 on Linux does not properly mitigate an unspecified flaw in an X server, which allows remote attackers to cause a denial of service (application crash) via vectors involving long messages.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-1412

больше 14 лет назад

sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-1411

больше 14 лет назад

Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-1409

больше 14 лет назад

Frams's Fast File EXchange (F*EX, aka fex) 20100208, and possibly other versions before 20110610, allows remote attackers to bypass authentication and upload arbitrary files via a request that lacks an authentication ID.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-1408

около 6 лет назад

ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2011-1407

больше 14 лет назад

The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-1406

больше 14 лет назад

Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-1439

Google Chrome before 11.0.696.57 on Linux does not properly isolate renderer processes, which has unspecified impact and remote attack vectors.

CVSS2: 6.8
0%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1438

Google Chrome before 11.0.696.57 allows remote attackers to bypass the Same Origin Policy via vectors involving blobs.

CVSS2: 7.5
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1437

Multiple integer overflows in Google Chrome before 11.0.696.57 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float rendering.

CVSS2: 6.8
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1436

Google Chrome before 11.0.696.57 on Linux does not properly interact with the X Window System, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 5
0%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1435

Google Chrome before 11.0.696.57 does not properly implement the tabs permission for extensions, which allows remote attackers to read local files via a crafted extension.

CVSS2: 5
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1434

Google Chrome before 11.0.696.57 does not ensure thread safety during handling of MIME data, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVSS2: 6.8
4%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1433

The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the session data in the database, which makes it easier for context-dependent attackers to obtain sensitive information by reading the _UserLogin and _UserPW fields.

CVSS2: 5
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-1431

The STARTTLS implementation in qmail-smtpd.c in qmail-smtpd in the netqmail-1.06-tls patch for netqmail 1.06 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

CVSS2: 6.8
7%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-1429

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

CVSS2: 5.8
1%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-1428

Wee Enhanced Environment for Chat (aka WeeChat) 0.3.4 and earlier does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL chat server via an arbitrary certificate, related to incorrect use of the GnuTLS API.

CVSS2: 5.8
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-1425

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.

CVSS2: 5.1
9%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1416

The Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246 allows attackers to read the contents of memory locations via unknown vectors, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011.

CVSS2: 5
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-1415

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-1290. Reason: This candidate is a duplicate of CVE-2011-1290. Notes: All CVE users should reference CVE-2011-1290 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

почти 15 лет назад
ubuntu логотип
CVE-2011-1413

Google Chrome before 10.0.648.127 on Linux does not properly mitigate an unspecified flaw in an X server, which allows remote attackers to cause a denial of service (application crash) via vectors involving long messages.

CVSS2: 5
2%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-1412

sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable.

CVSS2: 7.5
6%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1411

Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

CVSS2: 5.8
0%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1409

Frams's Fast File EXchange (F*EX, aka fex) 20100208, and possibly other versions before 20110610, allows remote attackers to bypass authentication and upload arbitrary files via a request that lacks an authentication ID.

CVSS2: 5
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1408

ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.

CVSS3: 8.2
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2011-1407

The DKIM implementation in Exim 4.7x before 4.76 permits matching for DKIM identities to apply to lookup items, instead of only strings, which allows remote attackers to execute arbitrary code or access a filesystem via a crafted identity.

CVSS2: 7.5
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1406

Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.

CVSS2: 4.3
0%
Низкий
больше 14 лет назад

Уязвимостей на страницу