|
296401
|
8.1 |
HIGH
Network
|
opensuse
|
sysconfig
|
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.…
|
CWE-20
Improper Input Validation
|
CVE-2011-4182
|
2024-11-21 10:31 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296402
|
7.5 |
HIGH
Network
|
opensuse
|
open_build_service
|
A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases are SUSE open build service up to and including v…
|
CWE-20
Improper Input Validation
|
CVE-2011-4181
|
2024-11-21 10:31 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296403
|
5.3 |
MEDIUM
Network
|
suse
|
suse_linux_enterprise_server suse_linux_enterprise_desktop
|
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in th…
|
CWE-310
Cryptographic Issues
|
CVE-2011-4190
|
2024-11-21 10:31 |
2018-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296404
|
9.8 |
CRITICAL
Network
|
packetfence
|
packetfence
|
html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentication via a crafted username.
|
CWE-90
LDAP Injection
|
CVE-2011-4069
|
2024-11-21 10:31 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296405
|
9.8 |
CRITICAL
Network
|
packetfence
|
packetfence
|
The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authentication via an empty password.
|
CWE-287
Improper Authentication
|
CVE-2011-4068
|
2024-11-21 10:31 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296406
|
- |
|
djangoproject
|
tastypie
|
The from_yaml method in serializers.py in Django Tastypie before 0.9.10 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to …
|
CWE-20
Improper Input Validation
|
CVE-2011-4104
|
2024-11-21 10:31 |
2014-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296407
|
- |
|
djangoproject
|
piston
|
emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the y…
|
CWE-20
Improper Input Validation
|
CVE-2011-4103
|
2024-11-21 10:31 |
2014-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296408
|
- |
|
bzip
|
bzip2
|
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by prec…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4089
|
2024-11-21 10:31 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296409
|
- |
|
redhat qemu
|
enterprise_linux_server_supplementary enterprise_linux qemu
|
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) an…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2011-4111
|
2024-11-21 10:31 |
2014-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296410
|
- |
|
redhat
|
sos
|
The sosreport utility in the Red Hat sos package before 1.7-9 and 2.x before 2.2-17 includes (1) Certificate-based Red Hat Network private entitlement keys and the (2) private key for the entitlement…
|
CWE-310
Cryptographic Issues
|
CVE-2011-4083
|
2024-11-21 10:31 |
2014-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|