|
298041
|
- |
|
puppetlabs puppet
|
puppet puppet_enterprise_users puppet_enterprise
|
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to …
|
CWE-20
Improper Input Validation
|
CVE-2011-3872
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298042
|
- |
|
puppetlabs puppet
|
puppet
|
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-3871
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298043
|
- |
|
puppetlabs puppet
|
puppet
|
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
|
CWE-59
Link Following
|
CVE-2011-3870
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298044
|
- |
|
puppetlabs puppet
|
puppet
|
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
|
CWE-59
Link Following
|
CVE-2011-3869
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298045
|
- |
|
puppetlabs puppet
|
puppet
|
Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locations via (1) a double…
|
CWE-22
Path Traversal
|
CVE-2011-3848
|
2024-11-21 10:31 |
2011-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298046
|
- |
|
google
|
chrome
|
Google Chrome before 15.0.874.102 does not properly restrict access to internal Google V8 functions, which allows remote attackers to cause a denial of service or possibly have unspecified other impa…
|
NVD-CWE-noinfo
|
CVE-2011-3891
|
2024-11-21 10:31 |
2011-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298047
|
- |
|
google
|
chrome
|
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to video source ha…
|
CWE-416
Use After Free
|
CVE-2011-3890
|
2024-11-21 10:31 |
2011-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298048
|
- |
|
google
|
chrome
|
Heap-based buffer overflow in the Web Audio implementation in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unkn…
|
CWE-787
Out-of-bounds Write
|
CVE-2011-3889
|
2024-11-21 10:31 |
2011-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298049
|
- |
|
google apple
|
chrome iphone_os itunes safari
|
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to e…
|
CWE-416
Use After Free
|
CVE-2011-3888
|
2024-11-21 10:31 |
2011-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298050
|
- |
|
google apple
|
chrome iphone_os safari
|
Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2011-3887
|
2024-11-21 10:31 |
2011-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|