|
297621
|
2.4 |
LOW
Physics
|
google
|
android
|
The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer.
|
CWE-200
Information Exposure
|
CVE-2011-2343
|
2024-11-21 10:28 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297622
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2011-2669
|
2024-11-21 10:28 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297623
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header
|
NVD-CWE-noinfo
|
CVE-2011-2668
|
2024-11-21 10:28 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297624
|
9.8 |
CRITICAL
Network
|
drupal
|
drupal data
|
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.
|
CWE-89
SQL Injection
|
CVE-2011-2715
|
2024-11-21 10:28 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297625
|
6.1 |
MEDIUM
Network
|
drupal
|
drupal data
|
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.
|
CWE-79
Cross-site Scripting
|
CVE-2011-2714
|
2024-11-21 10:28 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297626
|
6.1 |
MEDIUM
Network
|
snewscms
|
snews
|
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
|
CWE-79
Cross-site Scripting
|
CVE-2011-2706
|
2024-11-21 10:28 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297627
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
|
CWE-79
Cross-site Scripting
|
CVE-2011-2670
|
2024-11-21 10:28 |
2020-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297628
|
9.8 |
CRITICAL
Network
|
linux redhat
|
dhcp6c enterprise_linux
|
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP messag…
|
CWE-74
Injection
|
CVE-2011-2717
|
2024-11-21 10:28 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297629
|
9.8 |
CRITICAL
Network
|
vsftpd_project debian
|
vsftpd debian_linux
|
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
|
CWE-78
OS Command
|
CVE-2011-2523
|
2024-11-21 10:28 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297630
|
5.3 |
MEDIUM
Local
|
packagekit_project debian redhat
|
packagekit debian_linux enterprise_linux_server
|
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2011-2515
|
2024-11-21 10:28 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|