|
296621
|
- |
|
puppetlabs puppet
|
puppet
|
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-3871
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296622
|
- |
|
puppetlabs puppet
|
puppet
|
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
|
CWE-59
Link Following
|
CVE-2011-3870
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296623
|
- |
|
puppetlabs puppet
|
puppet
|
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
|
CWE-59
Link Following
|
CVE-2011-3869
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296624
|
- |
|
puppetlabs puppet
|
puppet
|
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double…
|
CWE-22
Path Traversal
|
CVE-2011-3848
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296625
|
- |
|
google
|
chrome
|
Google Chrome before 15.0.874.102 does not properly restrict access to internal Google V8 functions, which allows remote attackers to cause a denial of service or possibly have unspecified other impa…
|
NVD-CWE-noinfo
|
CVE-2011-3891
|
2024-11-21 10:31 |
2011-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296626
|
- |
|
google
|
chrome
|
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to video source ha…
|
CWE-416
Use After Free
|
CVE-2011-3890
|
2024-11-21 10:31 |
2011-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296627
|
- |
|
google
|
chrome
|
Heap-based buffer overflow in the Web Audio implementation in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unkn…
|
CWE-787
Out-of-bounds Write
|
CVE-2011-3889
|
2024-11-21 10:31 |
2011-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296628
|
- |
|
google apple
|
chrome iphone_os itunes safari
|
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to e…
|
CWE-416
Use After Free
|
CVE-2011-3888
|
2024-11-21 10:31 |
2011-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296629
|
- |
|
google apple
|
chrome iphone_os safari
|
Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2011-3887
|
2024-11-21 10:31 |
2011-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296630
|
- |
|
google
|
v8
|
Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers out-o…
|
CWE-20
Improper Input Validation
|
CVE-2011-3886
|
2024-11-21 10:31 |
2011-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|