4nuxd
_
Experience
Certifications
About
Writeups
News
Tools
Resources
Database
[Connect]
Vulnerability_Archives
CVE_
ARCHIVES
.DB
ARCHIVE_CHRONOLOGY.INDEX
STATUS: ONLINE
YEAR:
[2011]
Risk_Filter:
CRITICAL
HIGH
MEDIUM
LOW
Records:
4,172
Mode:
SECURE_QUERY
CVE-2011-4620
HIGH
Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote a
Discovered
Dec 31, 2011
CVE-2011-4617
LOW
virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary files via a symlink attack on a certain file in /tmp/.
Discovered
Dec 31, 2011
CVE-2011-1710
HIGH
Multiple integer overflows in the HTTP server in the Novell XTier framework 3.1.8 allow remote attackers to cause a denial of service (service crash)
Discovered
Dec 31, 2011
CVE-2011-5046
HIGH
The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
Discovered
Dec 30, 2011
CVE-2011-5045
MEDIUM
Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inject arbitrary web script or HTM
Discovered
Dec 30, 2011
CVE-2011-5044
HIGH
SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute arbitrary code by replacing Di
Discovered
Dec 30, 2011
CVE-2011-5043
MEDIUM
TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a b
Discovered
Dec 30, 2011
CVE-2011-5042
MEDIUM
Cross-site scripting (XSS) vulnerability in inc/lib/lib.base.php in SASHA 0.2.0 allows remote attackers to inject arbitrary web script or HTML via the
Discovered
Dec 30, 2011
CVE-2011-5041
MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) d
Discovered
Dec 30, 2011
CVE-2011-5040
MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitrary web script or HTML via the
Discovered
Dec 30, 2011
CVE-2011-5039
HIGH
Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL commands via the (1) username and (
Discovered
Dec 30, 2011
CVE-2011-5038
HIGH
SQL injection vulnerability in hitCode hitAppoint 4.5.17 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the userna
Discovered
Dec 30, 2011
CVE-2011-5037
MEDIUM
Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attacke
Discovered
Dec 30, 2011
CVE-2011-5036
MEDIUM
Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash
Discovered
Dec 30, 2011
CVE-2011-5035
MEDIUM
Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other pro
Discovered
Dec 30, 2011
CVE-2011-5034
HIGH
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, whi
Discovered
Dec 30, 2011
CVE-2011-4885
MEDIUM
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote
Discovered
Dec 30, 2011
CVE-2011-4838
MEDIUM
JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attac
Discovered
Dec 30, 2011
CVE-2011-4815
HIGH
Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-d
Discovered
Dec 30, 2011
CVE-2011-4462
MEDIUM
Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows
Discovered
Dec 30, 2011
1
2
3
...
Jump_To_Sector:
GO
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
2015
2014
2013
2012
2011
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998
1997
1996
1995
1994
1993
1992
1991
1990
1989
1988
2026 CVE Archives
2025 CVE Archives
2024 CVE Archives
2023 CVE Archives
2022 CVE Archives
2021 CVE Archives
2020 CVE Archives
2019 CVE Archives
2018 CVE Archives
2017 CVE Archives
2016 CVE Archives
2015 CVE Archives
2014 CVE Archives
2013 CVE Archives
2012 CVE Archives
2011 CVE Archives
2010 CVE Archives
2009 CVE Archives
2008 CVE Archives
2007 CVE Archives
2006 CVE Archives
2005 CVE Archives
2004 CVE Archives
2003 CVE Archives
2002 CVE Archives
2001 CVE Archives
2000 CVE Archives
1999 CVE Archives
1998 CVE Archives
1997 CVE Archives
1996 CVE Archives
1995 CVE Archives
1994 CVE Archives
1993 CVE Archives
1992 CVE Archives
1991 CVE Archives
1990 CVE Archives
1989 CVE Archives
1988 CVE Archives
CVE Database - Vulnerability Explorer