Latest CVE Feed
-
10.0
HIGHCVE-2011-2921
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.... Read more
Affected Products : ktsuss- EPSS Score: %71.59
- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2011-2916
qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-executable home directory, another local system user could obtain the private key used to connect to remote NX sessions.... Read more
Affected Products : qtnx- EPSS Score: %0.06
- Published: Nov. 15, 2019
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2011-2910
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow pos... Read more
- EPSS Score: %0.13
- Published: Nov. 15, 2019
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2011-2902
zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name.... Read more
- EPSS Score: %0.59
- Published: Jan. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-2897
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw... Read more
- EPSS Score: %0.98
- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2011-2863
Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.... Read more
Affected Products : chrome- EPSS Score: %0.19
- Published: Jun. 03, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2011-2808
A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed.... Read more
- EPSS Score: %0.42
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2011-2807
Incorrect handling of timer information in Timer.cpp in WebKit in Google Chrome before Blink M13.... Read more
- EPSS Score: %0.17
- Published: Nov. 07, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-2767
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HT... Read more
- EPSS Score: %4.88
- Published: Aug. 26, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2011-2765
pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.... Read more
Affected Products : pyro- EPSS Score: %0.43
- Published: Aug. 20, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2011-2726
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in co... Read more
- EPSS Score: %0.50
- Published: Nov. 15, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-2717
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.... Read more
- EPSS Score: %0.68
- Published: Nov. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-2715
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.... Read more
- EPSS Score: %0.50
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2011-2714
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.... Read more
- EPSS Score: %0.40
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2011-2706
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.... Read more
Affected Products : snews- EPSS Score: %0.23
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2011-2670
Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets... Read more
Affected Products : firefox- EPSS Score: %0.33
- Published: Jan. 13, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2011-2669
Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.... Read more
Affected Products : firefox- EPSS Score: %0.21
- Published: Jan. 21, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2011-2668
Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header... Read more
Affected Products : firefox- EPSS Score: %0.42
- Published: Jan. 21, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2011-2538
Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands.... Read more
Affected Products : telepresence_video_communication_server- EPSS Score: %2.96
- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.... Read more
- EPSS Score: %94.26
- Published: Nov. 27, 2019
- Modified: Nov. 21, 2024