Vulnerabilities (CVE)

Total 307385 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-3585 2 Redhat, Samba 2 Enterprise Linux, Samba 2024-11-21 1.9 LOW 4.7 MEDIUM
Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mounting outage) via a SIGKILL signal during a time window when the /etc/mtab~ file exists.
CVE-2011-3584 1 Guidestar 1 Wec Discussion Forum 2024-11-21 7.5 HIGH 9.8 CRITICAL
The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-supplied input.
CVE-2011-3583 1 Typo3 1 Typo3 2024-11-21 7.5 HIGH 9.8 CRITICAL
It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a SQL Injection vulnerability. This issue can only be exploited if two or more parameters are bound to the query and at least two come from user input.
CVE-2011-3582 1 Anelectron 1 Advanced Electron Forums 2024-11-21 6.8 MEDIUM 8.8 HIGH
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.
CVE-2011-3477 1 Symantec 4 Backup Exec System Recovery, Norton 360, Norton Ghost and 1 more 2024-11-21 4.9 MEDIUM 5.5 MEDIUM
GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a denial of service (system crash) via unspecified vectors.
CVE-2011-3374 1 Debian 2 Advanced Package Tool, Debian Linux 2024-11-21 4.3 MEDIUM 3.7 LOW
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
CVE-2011-3373 1 Drupal 1 Views Builk Operations 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS) attack.
CVE-2011-3370 1 Status 1 Statusnet 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
statusnet before 0.9.9 has XSS
CVE-2011-3355 2 Gnome, Linux 2 Evolution-data-server3, Linux Kernel 2024-11-21 4.3 MEDIUM 7.3 HIGH
evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials of the victim.
CVE-2011-3352 1 Ziku 1 Zikula 2024-11-21 3.5 LOW 4.8 MEDIUM
Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context of the affected website.
CVE-2011-3351 1 Openvas 1 Openvas-scanner 2024-11-21 6.6 MEDIUM 7.1 HIGH
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrite arbitrary files on the system.
CVE-2011-3350 1 Marmaro 1 Masqmail 2024-11-21 7.5 HIGH 9.8 CRITICAL
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
CVE-2011-3349 1 Lightdm Project 1 Lightdm 2024-11-21 7.2 HIGH 7.8 HIGH
lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.
CVE-2011-3336 4 Apple, Freebsd, Openbsd and 1 more 4 Mac Os X, Freebsd, Openbsd and 1 more 2024-11-21 7.8 HIGH 7.5 HIGH
regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.
CVE-2011-3269 1 Lexmark 168 25xxn, 25xxn Firmware, 6500e and 165 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut.
CVE-2011-3203 1 Jcow 1 Jcow Cms 2024-11-21 7.5 HIGH 9.8 CRITICAL
A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2.
CVE-2011-3202 1 Jcow 1 Jcow Cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists in the g parameter to index.php in Jcow CMS 4.2 and earlier.
CVE-2011-3183 1 Concretecms 1 Concrete Cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.
CVE-2011-3178 1 Opensuse 1 Open Build Service 2024-11-21 6.5 MEDIUM 8.1 HIGH
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to execute shellcode.
CVE-2011-3172 1 Suse 1 Suse Linux Enterprise Server 2024-11-21 10.0 HIGH 5.4 MEDIUM
A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.