Search Results (86397 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2011-3606 1 Redhat 1 Jboss Application Server 2024-11-21 5.4 Medium
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution.
CVE-2011-3595 1 Joomla 1 Joomla\! 2024-11-21 5.4 Medium
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.
CVE-2011-3373 1 Drupal 1 Views Builk Operations 2024-11-21 6.1 Medium
Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS) attack.
CVE-2011-3370 1 Status 1 Statusnet 2024-11-21 6.1 Medium
statusnet before 0.9.9 has XSS
CVE-2011-3352 1 Ziku 1 Zikula 2024-11-21 4.8 Medium
Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context of the affected website.
CVE-2011-3202 1 Jcow 1 Jcow Cms 2024-11-21 6.1 Medium
A Cross-Site Scripting (XSS) vulnerability exists in the g parameter to index.php in Jcow CMS 4.2 and earlier.
CVE-2011-3183 1 Concretecms 1 Concrete Cms 2024-11-21 6.1 Medium
A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.
CVE-2011-3178 1 Opensuse 1 Open Build Service 2024-11-21 N/A
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to execute shellcode.
CVE-2011-2935 1 Elgg 1 Elgg 2024-11-21 6.1 Medium
Elgg through 1.7.10 has XSS
CVE-2011-2807 1 Google 1 Blink 2024-11-21 6.5 Medium
Incorrect handling of timer information in Timer.cpp in WebKit in Google Chrome before Blink M13.
CVE-2011-2717 2 Linux, Redhat 2 Dhcp6c, Enterprise Linux 2024-11-21 9.8 Critical
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.
CVE-2011-2714 1 Drupal 2 Data, Drupal 2024-11-21 6.1 Medium
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.
CVE-2011-2706 1 Snewscms 1 Snews 2024-11-21 6.1 Medium
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
CVE-2011-2670 1 Mozilla 1 Firefox 2024-11-21 6.1 Medium
Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
CVE-2011-2538 1 Cisco 1 Telepresence Video Communication Server 2024-11-21 7.2 High
Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands.
CVE-2011-2523 2 Debian, Vsftpd Project 2 Debian Linux, Vsftpd 2024-11-21 9.8 Critical
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
CVE-2011-2515 3 Debian, Packagekit Project, Redhat 3 Debian Linux, Packagekit, Enterprise Linux Server 2024-11-21 5.3 Medium
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
CVE-2011-2499 1 Mambo-foundation 1 Mambo Cms 2024-11-21 6.1 Medium
Mambo CMS through 4.6.5 has multiple XSS.
CVE-2011-2498 2 Canonical, Linux 2 Ubuntu Linux, Linux Kernel 2024-11-21 5.5 Medium
The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of service (memory consumption) by triggering creation of PTE pages.
CVE-2011-2337 1 Google 1 Blink 2024-11-21 9.8 Critical
A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.