Search Results (323364 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2011-1460 1 Google 1 Blink 2024-11-21 9.8 Critical
WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.
CVE-2011-1459 1 Google 1 Blink 2024-11-21 6.5 Medium
The WebKit::WebPluginContainerImpl::handleEvent function in Google Chrome before Blink M11 allows an attacker to cause a denial of service (crash) via the htmlpluginelement.cpp plugin.
CVE-2011-1408 2 Debian, Ikiwiki 2 Debian Linux, Ikiwiki 2024-11-21 8.2 High
ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.
CVE-2011-1298 2 Apple, Google 2 Macos, Blink 2024-11-21 7.5 High
An Integer Overflow exists in WebKit in Google Chrome before Blink M11 in the macOS WebCore::GraphicsContext::fillRect function.
CVE-2011-1151 1 Joomla 1 Joomla\! 2024-11-21 9.1 Critical
Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.
CVE-2011-1150 1 Bbpress 1 Bbpress 2024-11-21 6.1 Medium
bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.
CVE-2011-1145 4 Debian, Opensuse, Redhat and 1 more 4 Debian Linux, Opensuse, Enterprise Linux and 1 more 2024-11-21 7.8 High
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
CVE-2011-1136 2 Debian, Tesseract Project 2 Debian Linux, Tesseract 2024-11-21 4.7 Medium
In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.
CVE-2011-1135 1 S9y 1 Serendipity 2024-11-21 6.1 Medium
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/ImageManager/manager.php.
CVE-2011-1134 1 S9y 1 Serendipity 2024-11-21 9.8 Critical
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.
CVE-2011-1133 1 S9y 1 Serendipity 2024-11-21 6.1 Medium
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php.
CVE-2011-1086 1 Openfiler 1 Openfiler 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitrary web script or HTML via the device parameter.
CVE-2011-1085 1 Smoothwall 1 Smoothwall Express 2024-11-21 8.8 High
CSRF vulnerability in Smoothwall Express 3.
CVE-2011-1084 1 Smoothwall 1 Smoothwall Express 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Smoothwall Express 3.
CVE-2011-1075 1 Freebsd 1 Freebsd 2024-11-21 3.7 Low
FreeBSD's crontab calculates the MD5 sum of the previous and new cronjob to determine if any changes have been made before copying the new version in. In particular, it uses the MD5File() function, which takes a pathname as an argument, and is called with euid 0. A race condition in this process may lead to an arbitrary MD5 comparison regardless of the read permissions.
CVE-2011-1070 2 Debian, V86d Project 2 Debian Linux, V86d 2024-11-21 7.8 High
v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mode and potentially other consequences.
CVE-2011-1069 1 Phpshop 1 Phpshop 2024-11-21 6.1 Medium
PHPShop through 0.8.1 has XSS.
CVE-2011-1028 2 Debian, Smarty 2 Debian Linux, Smarty 2024-11-21 9.8 Critical
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
CVE-2011-1009 1 Vanillaforums 1 Vanilla 2024-11-21 6.1 Medium
Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.
CVE-2011-10004 1 Reciply Project 1 Reciply 2024-11-21 6.3 Medium
A vulnerability was found in reciply Plugin up to 1.1.7 on WordPress. It has been rated as critical. This issue affects some unknown processing of the file uploadImage.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. Upgrading to version 1.1.8 is able to address this issue. The identifier of the patch is e3ff616dc08d3aadff9253f1085e13f677d0c676. It is recommended to upgrade the affected component. The identifier VDB-242189 was assigned to this vulnerability.