Search Results (23482 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2011-4124 1 Calibre-ebook 1 Calibre 2024-11-21 9.8 Critical
Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.
CVE-2011-4120 3 Debian, Linux, Yubico 3 Debian Linux, Linux Kernel, Pam Module 2024-11-21 9.8 Critical
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.
CVE-2011-4088 3 Abrt Project, Fedoraproject, Redhat 6 Abrt, Fedora, Enterprise Linux and 3 more 2024-11-21 7.5 High
ABRT might allow attackers to obtain sensitive information from crash reports.
CVE-2011-4076 1 Openstack 1 Nova 2024-11-21 5.9 Medium
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle over https could allow an attacker to easily obtain the EC2_SECRET_KEY. An attacker could also presumably brute force values for EC2_ACCESS_KEY.
CVE-2011-3901 1 Google 1 Android 2024-11-21 7.5 High
Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.
CVE-2011-3613 1 Vanillaforums 1 Vanilla 2024-11-21 7.5 High
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
CVE-2011-3611 1 Usebb 1 Usebb 2024-11-21 7.2 High
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
CVE-2011-3477 1 Symantec 4 Backup Exec System Recovery, Norton 360, Norton Ghost and 1 more 2024-11-21 N/A
GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a denial of service (system crash) via unspecified vectors.
CVE-2011-3269 1 Lexmark 168 25xxn, 25xxn Firmware, 6500e and 165 more 2024-11-21 7.5 High
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut.
CVE-2011-3203 1 Jcow 1 Jcow Cms 2024-11-21 9.8 Critical
A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2.
CVE-2011-3147 1 Openstack 1 Nova 2024-11-21 8.6 High
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.
CVE-2011-2922 1 Ktsuss Project 1 Ktsuss 2024-11-21 7.8 High
ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privileges to root and use the "GTK_MODULES" environment variable to possibly execute arbitrary code.
CVE-2011-2902 2 Debian, Glyphandcog 2 Debian Linux, Xpdf 2024-11-21 N/A
zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name.
CVE-2011-2897 3 Debian, Gnome, Redhat 3 Debian Linux, Gdk-pixbuf, Enterprise Linux 2024-11-21 9.8 Critical
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
CVE-2011-2863 1 Google 1 Chrome 2024-11-21 6.5 Medium
Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2011-2808 1 Google 1 Blink 2024-11-21 6.5 Medium
A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed.
CVE-2011-2480 2 Freebsd, Netbsd 2 Freebsd, Netbsd 2024-11-21 7.5 High
Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signedness error in the IEEE80211_IOC_CHANINFO ioctl allows a local unprivileged user to cause the kernel to copy large amounts of kernel memory back to the user, disclosing potentially sensitive information.
CVE-2011-2343 1 Google 1 Android 2024-11-21 2.4 Low
The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer.
CVE-2011-1934 2 Debian, Lilo Project 2 Debian Linux, Lilo 2024-11-21 4.3 Medium
lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1.
CVE-2011-1028 2 Debian, Smarty 2 Debian Linux, Smarty 2024-11-21 9.8 Critical
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.