|
296571
|
6.5 |
MEDIUM
Network
|
google
|
blink
|
Incorrect handling of timer information in Timer.cpp in WebKit in Google Chrome before Blink M13.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2011-2807
|
2024-11-21 10:29 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296572
|
6.5 |
MEDIUM
Network
|
google
|
blink
|
A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed.
|
CWE-20
Improper Input Validation
|
CVE-2011-2808
|
2024-11-21 10:29 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296573
|
5.9 |
MEDIUM
Network
|
canonical
|
selinux
|
The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If the OS kernel does not have symlink protections then an attacker can cause a zero…
|
CWE-693
Protection Mechanism Failure
|
CVE-2011-3151
|
2024-11-21 10:29 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296574
|
8.6 |
HIGH
Network
|
openstack
|
nova
|
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.
|
CWE-200
Information Exposure
|
CVE-2011-3147
|
2024-11-21 10:29 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296575
|
9.8 |
CRITICAL
Network
|
mount.ecrpytfs_private_project
|
mount.ecrpytfs_private
|
When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of t…
|
CWE-254
7PK - Security Features
|
CVE-2011-3145
|
2024-11-21 10:29 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296576
|
9.8 |
CRITICAL
Network
|
suse
|
suse_linux_enterprise_server
|
A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-3172
|
2024-11-21 10:29 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296577
|
8.8 |
HIGH
Network
|
opensuse
|
open_build_service
|
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to execute shellcode.
|
CWE-94
Code Injection
|
CVE-2011-3178
|
2024-11-21 10:29 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296578
|
5.3 |
MEDIUM
Network
|
glyphandcog debian
|
xpdf debian_linux
|
zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary fi…
|
CWE-20
Improper Input Validation
|
CVE-2011-2902
|
2024-11-21 10:29 |
2018-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296579
|
7.8 |
HIGH
Local
|
yast
|
yast2
|
The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network configuration files, like passwords for wireless network…
|
CWE-200
Information Exposure
|
CVE-2011-3177
|
2024-11-21 10:29 |
2017-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296580
|
- |
|
megalab
|
the_uploader
|
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2011-2944
|
2024-11-21 10:29 |
2014-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|