Search

Search Results (334729 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2011-4183 1 Opensuse 1 Open Build Service 2024-11-21 N/A
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.
CVE-2011-4182 1 Opensuse 1 Sysconfig 2024-11-21 N/A
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1.
CVE-2011-4181 1 Opensuse 1 Open Build Service 2024-11-21 7.5 High
A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases are SUSE open build service up to and including version 2.1.15 (for 2.1) and before version 2.3.
CVE-2011-4126 1 Calibre-ebook 1 Calibre 2024-11-21 8.1 High
Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.
CVE-2011-4125 1 Calibre-ebook 1 Calibre 2024-11-21 9.8 Critical
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.
CVE-2011-4124 1 Calibre-ebook 1 Calibre 2024-11-21 9.8 Critical
Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.
CVE-2011-4121 1 Ruby-lang 1 Ruby 2024-11-21 9.8 Critical
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.
CVE-2011-4120 3 Debian, Linux, Yubico 3 Debian Linux, Linux Kernel, Pam Module 2024-11-21 9.8 Critical
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.
CVE-2011-4119 1 Inria 1 Caml-light 2024-11-21 9.8 Critical
caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.
CVE-2011-4117 1 Cpan 1 Batch\ 2024-11-21 7.5 High
The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files.
CVE-2011-4115 1 Cpan 1 Parallel\ 2024-11-21 7.5 High
Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.
CVE-2011-4095 1 Jara Project 1 Jara 2024-11-21 6.1 Medium
Jara 1.6 has an XSS vulnerability
CVE-2011-4094 1 Jara Project 1 Jara 2024-11-21 9.8 Critical
Jara 1.6 has a SQL injection vulnerability.
CVE-2011-4090 1 S9y 1 Serendipity 2024-11-21 6.1 Medium
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
CVE-2011-4088 3 Abrt Project, Fedoraproject, Redhat 6 Abrt, Fedora, Enterprise Linux and 3 more 2024-11-21 7.5 High
ABRT might allow attackers to obtain sensitive information from crash reports.
CVE-2011-4082 2 Debian, Phpldapadmin Project 2 Debian Linux, Phpldapadmin 2024-11-21 7.5 High
A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via specially-crafted request.
CVE-2011-4076 1 Openstack 1 Nova 2024-11-21 5.9 Medium
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle over https could allow an attacker to easily obtain the EC2_SECRET_KEY. An attacker could also presumably brute force values for EC2_ACCESS_KEY.
CVE-2011-4069 1 Packetfence 1 Packetfence 2024-11-21 N/A
html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentication via a crafted username.
CVE-2011-4068 1 Packetfence 1 Packetfence 2024-11-21 N/A
The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authentication via an empty password.
CVE-2011-3923 2 Apache, Redhat 2 Struts, Jboss Enterprise Web Server 2024-11-21 9.8 Critical
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.