|
296841
|
8.8 |
HIGH
Network
|
anelectron
|
advanced_electron_forums
|
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.
|
CWE-352
Origin Validation Error
|
CVE-2011-3582
|
2024-11-21 10:30 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296842
|
4.7 |
MEDIUM
Local
|
samba redhat
|
samba enterprise_linux
|
Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mounting outage) via a SIGKILL signal during a time window whe…
|
CWE-362
Race Condition
|
CVE-2011-3585
|
2024-11-21 10:30 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296843
|
7.1 |
HIGH
Local
|
hardlink_project redhat debian
|
hardlink enterprise_linux debian_linux
|
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
|
CWE-59
Link Following
|
CVE-2011-3632
|
2024-11-21 10:30 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296844
|
5.3 |
MEDIUM
Network
|
ruby-lang
|
ruby
|
Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server headers in requests, which might allow remote …
|
CWE-74
Injection
|
CVE-2011-3624
|
2024-11-21 10:30 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296845
|
6.5 |
MEDIUM
Network
|
tahoe-lafs debian
|
tahoe-lafs debian_linux
|
Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.
|
CWE-863
Incorrect Authorization
|
CVE-2011-3617
|
2024-11-21 10:30 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296846
|
6.5 |
MEDIUM
Network
|
redhat
|
jboss_application_server
|
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP…
|
CWE-352
Origin Validation Error
|
CVE-2011-3609
|
2024-11-21 10:30 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296847
|
5.4 |
MEDIUM
Network
|
redhat
|
jboss_application_server
|
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick th…
|
CWE-79
Cross-site Scripting
|
CVE-2011-3606
|
2024-11-21 10:30 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296848
|
7.5 |
HIGH
Network
|
apache
|
ofbiz
|
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of fi…
|
CWE-611
XXE
|
CVE-2011-3600
|
2024-11-21 10:30 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296849
|
8.8 |
HIGH
Network
|
hardlink_project redhat debian
|
hardlink enterprise_linux debian_linux
|
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2011-3631
|
2024-11-21 10:30 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296850
|
8.8 |
HIGH
Network
|
hardlink_project redhat debian
|
hardlink enterprise_linux debian_linux
|
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a special…
|
CWE-787
Out-of-bounds Write
|
CVE-2011-3630
|
2024-11-21 10:30 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|