Latest CVE Feed
-
7.5
HIGHCVE-2011-4310
The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.23
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2011-4190
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remot... Read more
- EPSS Score: %0.23
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-4183
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.... Read more
Affected Products : open_build_service- EPSS Score: %0.37
- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2011-4182
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1.... Read more
Affected Products : sysconfig- EPSS Score: %0.57
- Published: Jun. 12, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2011-4181
A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases are SUSE open build service up to and including version 2.1.15 (for 2.1) and before version 2.3.... Read more
Affected Products : open_build_service- EPSS Score: %0.23
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2011-4126
Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.... Read more
Affected Products : calibre- EPSS Score: %0.47
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-4125
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.... Read more
Affected Products : calibre- EPSS Score: %0.71
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-4124
Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.... Read more
Affected Products : calibre- EPSS Score: %0.61
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-4121
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, dep... Read more
Affected Products : ruby- EPSS Score: %0.10
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-4120
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common auth... Read more
- EPSS Score: %1.48
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-4119
caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.... Read more
Affected Products : caml-light- EPSS Score: %0.53
- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2011-4117
The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files.... Read more
Affected Products : batch\- EPSS Score: %0.38
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2011-4115
Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.... Read more
Affected Products : parallel\- EPSS Score: %0.39
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- EPSS Score: %0.83
- Published: Jan. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %5.60
- Published: Jan. 21, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2011-4090
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.... Read more
Affected Products : serendipity- EPSS Score: %2.26
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2011-4088
ABRT might allow attackers to obtain sensitive information from crash reports.... Read more
- EPSS Score: %0.74
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2011-4082
A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via specially-crafted request.... Read more
- EPSS Score: %0.92
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2011-4076
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle over https could al... Read more
Affected Products : nova- EPSS Score: %0.41
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2011-4069
html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentication via a crafted username.... Read more
Affected Products : packetfence- EPSS Score: %0.88
- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024