|
297351
|
- |
|
inventivetec
|
mediacast
|
Multiple cross-site scripting (XSS) vulnerabilities in the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier allow remote attackers to inject arbitrary web script or HTML via…
|
CWE-79
Cross-site Scripting
|
CVE-2011-2078
|
2024-11-21 10:27 |
2011-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297352
|
- |
|
inventivetec
|
mediacast
|
The default configuration of the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier enables external TCP connections to port 10000, instead of connections only from 127.0.0.1,…
|
CWE-16
Configuration
|
CVE-2011-2077
|
2024-11-21 10:27 |
2011-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297353
|
- |
|
inventivetec
|
mediacast
|
MediaCAST 8 and earlier stores passwords in cleartext, which makes it easier for context-dependent attackers to obtain sensitive information by reading an unspecified password data store, a different…
|
CWE-200
Information Exposure
|
CVE-2011-2076
|
2024-11-21 10:27 |
2011-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297354
|
- |
|
google
|
chrome
|
Unspecified vulnerability in Google Chrome 11.0.696.65 on Windows 7 SP1 allows remote attackers to execute arbitrary code via unknown vectors. NOTE: as of 20110510, the only disclosure is a vague ad…
|
NVD-CWE-noinfo
|
CVE-2011-2075
|
2024-11-21 10:27 |
2011-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297355
|
- |
|
skype
|
skype
|
Unspecified vulnerability in the client in Skype 5.x before 5.1.0.922 on Mac OS X allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via a cr…
|
NVD-CWE-noinfo
|
CVE-2011-2074
|
2024-11-21 10:27 |
2011-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297356
|
- |
|
opera
|
opera_browser
|
The VEGAOpBitmap::AddLine function in Opera before 10.61 does not properly initialize memory during processing of the SIZE attribute of a SELECT element, which allows remote attackers to trigger an i…
|
CWE-20
Improper Input Validation
|
CVE-2011-1824
|
2024-11-21 10:27 |
2011-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297357
|
- |
|
isc
|
bind
|
ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RRSIG qu…
|
CWE-399
Resource Management Errors
|
CVE-2011-1907
|
2024-11-21 10:27 |
2011-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297358
|
- |
|
vmware
|
vcenter esxi esx
|
The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMware ESX 4.x before 4.1…
|
CWE-310
Cryptographic Issues
|
CVE-2011-1789
|
2024-11-21 10:27 |
2011-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297359
|
- |
|
vmware
|
vcenter
|
vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2011-1788
|
2024-11-21 10:27 |
2011-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297360
|
- |
|
linux redhat
|
linux_kernel enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_desktop enterprise_linux_eus enterprise_linux_aus
|
The agp_generic_remove_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 does not validate a certain start parameter, which allows local users to gain privileges or ca…
|
CWE-20
Improper Input Validation
|
CVE-2011-2022
|
2024-11-21 10:27 |
2011-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|