Search Results (25746 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2012-1124 1 Phxeventmanager Project 1 Phxeventmanager 2024-11-21 9.8 Critical
SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.
CVE-2012-10001 1 Limit Login Attempts Project 1 Limit Login Attempts 2024-11-21 9.8 Critical
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.
CVE-2012-0828 3 Gnome, Xchat, Xchat-wdk 3 Gtk, Xchat, Xchat-wdk 2024-11-21 9.8 Critical
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).
CVE-2012-0824 1 Gnu 1 Gnusound 2024-11-21 9.8 Critical
gnusound 0.7.5 has format string issue
CVE-2012-0694 1 Sugarcrm 1 Sugarcrm 2024-11-21 9.8 Critical
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
CVE-2011-5331 1 Distributed Ruby Project 1 Distributed Ruby 2024-11-21 9.8 Critical
Distributed Ruby (aka DRuby) 1.8 mishandles instance_eval.
CVE-2011-5330 1 Distributed Ruby Project 1 Distributed Ruby 2024-11-21 9.8 Critical
Distributed Ruby (aka DRuby) 1.8 mishandles the sending of syscalls.
CVE-2011-5327 1 Linux 1 Linux Kernel 2024-11-21 9.8 Critical
In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function could result in at least memory corruption.
CVE-2011-5266 1 Imperva 1 Securesphere Web Application Firewall 2024-11-21 9.8 Critical
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.
CVE-2011-5020 1 Online Tv Database Project 1 Online Tv Database 2024-11-21 9.8 Critical
An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.
CVE-2011-4943 1 Impresspages 1 Impresspages Cms 2024-11-21 9.8 Critical
ImpressPages CMS v1.0.12 has Unspecified Remote Code Execution (fixed in v1.0.13)
CVE-2011-4908 1 Tiny 1 Tinybrowser 2024-11-21 9.8 Critical
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
CVE-2011-4906 1 Tiny 1 Tinybrowser 2024-11-21 9.8 Critical
Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
CVE-2011-4628 1 Typo3 1 Typo3 2024-11-21 9.8 Critical
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.
CVE-2011-4574 1 Polarssl 1 Polarssl 2024-11-21 9.8 Critical
PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the RDTSC instruction). This instruction can be virtualized, and some virtual machine hosts have chosen to disable this instruction, returning 0s or predictable results.
CVE-2011-4125 1 Calibre-ebook 1 Calibre 2024-11-21 9.8 Critical
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.
CVE-2011-4124 1 Calibre-ebook 1 Calibre 2024-11-21 9.8 Critical
Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.
CVE-2011-4121 1 Ruby-lang 1 Ruby 2024-11-21 9.8 Critical
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.
CVE-2011-4120 3 Debian, Linux, Yubico 3 Debian Linux, Linux Kernel, Pam Module 2024-11-21 9.8 Critical
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.
CVE-2011-4119 1 Inria 1 Caml-light 2024-11-21 9.8 Critical
caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.