Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 76 769

Количество 76 769

ubuntu логотип

CVE-2011-4121

почти 7 лет назад

The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4118

почти 15 лет назад

Mahara before 1.4.1, when MNet (aka the Moodle network feature) is used, allows remote authenticated users to gain privileges via a jump to an XMLRPC target.

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2011-4116

больше 6 лет назад

_is_safe in the File::Temp module for Perl does not properly handle symlinks.

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4115

больше 6 лет назад

Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4114

больше 14 лет назад

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

CVSS2: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4113

больше 14 лет назад

SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4112

больше 14 лет назад

The net subsystem in the Linux kernel before 3.1 does not properly restrict use of the IFF_TX_SKB_SHARING flag, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability to access /proc/net/pktgen/pgctrl, and then using the pktgen package in conjunction with a bridge device for a VLAN interface.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4111

больше 12 лет назад

Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4110

больше 14 лет назад

The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2011-4109

больше 14 лет назад

Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an unspecified impact by triggering failure of a policy check.

CVSS2: 9.3
EPSS: Средний
ubuntu логотип

CVE-2011-4108

больше 14 лет назад

The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2011-4107

почти 15 лет назад

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2011-4105

больше 14 лет назад

LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority.

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2011-4104

почти 12 лет назад

The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4103

почти 12 лет назад

emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4102

почти 15 лет назад

Heap-based buffer overflow in the erf_read_header function in wiretap/erf.c in the ERF file parser in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (application crash) via a malformed file.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4101

почти 15 лет назад

The dissect_infiniband_common function in epan/dissectors/packet-infiniband.c in the Infiniband dissector in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4100

почти 15 лет назад

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4099

больше 12 лет назад

The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restrictions via unspecified vectors.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2011-4098

около 13 лет назад

The fallocate implementation in the GFS2 filesystem in the Linux kernel before 3.2 relies on the page cache, which might allow local users to cause a denial of service by preallocating blocks in certain situations involving insufficient memory.

CVSS2: 1.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-4121

The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.

CVSS3: 9.8
3%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2011-4118

Mahara before 1.4.1, when MNet (aka the Moodle network feature) is used, allows remote authenticated users to gain privileges via a jump to an XMLRPC target.

CVSS2: 6
2%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-4116

_is_safe in the File::Temp module for Perl does not properly handle symlinks.

CVSS3: 3.3
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2011-4115

Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2011-4114

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

CVSS2: 3.3
0%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4113

SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."

CVSS2: 7.5
2%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4112

The net subsystem in the Linux kernel before 3.1 does not properly restrict use of the IFF_TX_SKB_SHARING flag, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability to access /proc/net/pktgen/pgctrl, and then using the pktgen package in conjunction with a bridge device for a VLAN interface.

CVSS3: 5.5
0%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4111

Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.

CVSS2: 6.8
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2011-4110

The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."

CVSS2: 2.1
0%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4109

Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an unspecified impact by triggering failure of a policy check.

CVSS2: 9.3
17%
Средний
больше 14 лет назад
ubuntu логотип
CVE-2011-4108

The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.

CVSS2: 4.3
16%
Средний
больше 14 лет назад
ubuntu логотип
CVE-2011-4107

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

CVSS3: 6.5
13%
Средний
почти 15 лет назад
ubuntu логотип
CVE-2011-4105

LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority.

CVSS2: 1.9
0%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-4104

The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

CVSS2: 7.5
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-4103

emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.

CVSS2: 7.5
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-4102

Heap-based buffer overflow in the erf_read_header function in wiretap/erf.c in the ERF file parser in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (application crash) via a malformed file.

CVSS2: 4.3
3%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-4101

The dissect_infiniband_common function in epan/dissectors/packet-infiniband.c in the Infiniband dissector in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-4100

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-4099

The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restrictions via unspecified vectors.

CVSS2: 4.6
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2011-4098

The fallocate implementation in the GFS2 filesystem in the Linux kernel before 3.2 relies on the page cache, which might allow local users to cause a denial of service by preallocating blocks in certain situations involving insufficient memory.

CVSS2: 1.9
0%
Низкий
около 13 лет назад

Уязвимостей на страницу