Latest CVE Feed
-
7.5
HIGHCVE-2011-3269
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut.... Read more
Affected Products : x46x_firmware c950_firmware 6500e_firmware c734_firmware c736_firmware w850_firmware 25xxn c510 c540 c546 +158 more products- EPSS Score: %0.32
- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-3203
A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2.... Read more
Affected Products : jcow_cms- EPSS Score: %0.41
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2011-3202
A Cross-Site Scripting (XSS) vulnerability exists in the g parameter to index.php in Jcow CMS 4.2 and earlier.... Read more
Affected Products : jcow_cms- EPSS Score: %0.23
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2011-3183
A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.... Read more
Affected Products : concrete_cms- EPSS Score: %0.24
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2011-3178
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to execute shellcode.... Read more
- EPSS Score: %0.33
- Published: Mar. 20, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-3172
A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.... Read more
Affected Products : suse_linux_enterprise_server- EPSS Score: %0.23
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2011-3151
The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If the OS kernel does not have symlink protections then an attacker can cause a zero byte file to be allocated on any writable filesystem.... Read more
Affected Products : selinux- EPSS Score: %0.16
- Published: Apr. 22, 2019
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2011-3147
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.... Read more
Affected Products : nova- EPSS Score: %0.18
- Published: Apr. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-3145
When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of the user running mount.ecryptfs_private.... Read more
Affected Products : mount.ecrpytfs_private- EPSS Score: %0.23
- Published: Apr. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-2936
Elgg through 1.7.10 has a SQL injection vulnerability... Read more
Affected Products : elgg- EPSS Score: %0.32
- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- EPSS Score: %0.31
- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2011-2934
A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmation for sensitive transactions.... Read more
Affected Products : websitebaker- EPSS Score: %0.14
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2011-2933
An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5, and .phtl extensions.... Read more
Affected Products : websitebaker- EPSS Score: %0.45
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2011-2924
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting ar... Read more
- EPSS Score: %0.13
- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2011-2923
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbit... Read more
- EPSS Score: %0.19
- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2011-2922
ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privileges to root and use the "GTK_MODULES" environment variable to possibly execute arbitrary code.... Read more
Affected Products : ktsuss- EPSS Score: %0.15
- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-2921
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.... Read more
Affected Products : ktsuss- EPSS Score: %71.59
- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2011-2916
qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-executable home directory, another local system user could obtain the private key used to connect to remote NX sessions.... Read more
Affected Products : qtnx- EPSS Score: %0.06
- Published: Nov. 15, 2019
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2011-2910
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow pos... Read more
- EPSS Score: %0.13
- Published: Nov. 15, 2019
- Modified: Nov. 21, 2024