Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 76 769

Количество 76 769

ubuntu логотип

CVE-2011-4919

почти 7 лет назад

mpack 1.6 has information disclosure via eavesdropping on mails sent by other users

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4917

больше 4 лет назад

In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4916

около 4 лет назад

Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4915

больше 6 лет назад

fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4914

около 14 лет назад

The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a ROSE socket.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2011-4913

около 14 лет назад

The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4905

больше 14 лет назад

Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-4904

почти 7 лет назад

TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4903

почти 7 лет назад

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2011-4902

почти 7 лет назад

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4901

почти 7 лет назад

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4900

почти 7 лет назад

TYPO3 before 4.5.4 allows Information Disclosure in the backend.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4899

больше 14 лет назад

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname parameters, and subsequently conduct static code injection and cross-site scripting (XSS) attacks via (1) an HTTP request or (2) a MySQL query. NOTE: the vendor disputes the significance of this issue; however, remote code execution makes the issue important in many realistic environments

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4898

больше 14 лет назад

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-4897

больше 14 лет назад

Tor before 0.2.2.25-alpha, when configured as a relay without the Nickname configuration option, uses the local hostname as the Nickname value, which allows remote attackers to obtain potentially sensitive information by reading this value.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4896

больше 14 лет назад

Tor before 0.2.2.24-alpha continues to use a reachable bridge that was previously configured but is not currently configured, which might allow remote attackers to obtain sensitive information about clients in opportunistic circumstances by monitoring network traffic to the bridge port.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4895

больше 14 лет назад

Tor before 0.2.2.34, when configured as a bridge, sets up circuits through a process different from the process used by a client, which makes it easier for remote attackers to enumerate bridges by observing circuit building.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4894

больше 14 лет назад

Tor before 0.2.2.34, when configured as a bridge, uses direct DirPort access instead of a Tor TLS connection for a directory fetch, which makes it easier for remote attackers to enumerate bridges by observing DirPort connections.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4885

больше 14 лет назад

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2011-4869

больше 14 лет назад

validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528.

CVSS2: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-4919

mpack 1.6 has information disclosure via eavesdropping on mails sent by other users

CVSS3: 7.5
3%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2011-4917

In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2011-4916

Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2011-4915

fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.

CVSS3: 5.5
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2011-4914

The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a ROSE socket.

CVSS2: 6.4
9%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-4913

The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to a ROSE socket, or (2) conduct stack-based buffer overflow attacks via a large length value in data sent to a ROSE socket.

CVSS2: 7.8
4%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-4905

Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.

CVSS2: 5
8%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4904

TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.

CVSS3: 6.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2011-4903

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the RemoveXSS function.

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2011-4902

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to delete arbitrary files on the webserver.

CVSS3: 6.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2011-4901

TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.

CVSS3: 6.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2011-4900

TYPO3 before 4.5.4 allows Information Disclosure in the backend.

CVSS3: 6.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2011-4899

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname parameters, and subsequently conduct static code injection and cross-site scripting (XSS) attacks via (1) an HTTP request or (2) a MySQL query. NOTE: the vendor disputes the significance of this issue; however, remote code execution makes the issue important in many realistic environments

CVSS2: 7.5
9%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4898

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective

CVSS2: 5
10%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4897

Tor before 0.2.2.25-alpha, when configured as a relay without the Nickname configuration option, uses the local hostname as the Nickname value, which allows remote attackers to obtain potentially sensitive information by reading this value.

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4896

Tor before 0.2.2.24-alpha continues to use a reachable bridge that was previously configured but is not currently configured, which might allow remote attackers to obtain sensitive information about clients in opportunistic circumstances by monitoring network traffic to the bridge port.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4895

Tor before 0.2.2.34, when configured as a bridge, sets up circuits through a process different from the process used by a client, which makes it easier for remote attackers to enumerate bridges by observing circuit building.

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4894

Tor before 0.2.2.34, when configured as a bridge, uses direct DirPort access instead of a Tor TLS connection for a directory fetch, which makes it easier for remote attackers to enumerate bridges by observing DirPort connections.

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4885

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS2: 5
83%
Высокий
больше 14 лет назад
ubuntu логотип
CVE-2011-4869

validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528.

CVSS2: 7.8
3%
Низкий
больше 14 лет назад

Уязвимостей на страницу