LiveActive security incident?Get immediate response
CVE archive

January 2011

Browse CVE records published in January 2011, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 396 matching CVEs · Page 4 of 8.

Unknown · CVSS Not scored

CVE-2011-4785: Directory traversal vulnerability in the HP-ChaiSOE/1.0 web server on the HP LaserJet P3015 printer with fi...

Directory traversal vulnerability in the HP-ChaiSOE/1.0 web server on the HP LaserJet P3015 printer with firmware before 07.080.3, LaserJet 4650 printer with firmware 07.006.0, and LaserJet 2430 printer with firmware 08.113.0_I35128 allows remote attackers to read arbitrary files via unspecified vectors, a different vulnerability than CVE-2008-4419.

Published Jan 10, 2012 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2011-4644: Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality wi...

Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does not support authentication, which allows remote attackers to (1) read arbitrary files via a management-console session that leverages the ability to create crafted data sources, or (2) execute management commands via an HTTP request.

Published Jan 3, 2012 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2011-4642: mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to...

mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python classes, which allows remote authenticated administrators to execute arbitrary code by leveraging the sys module in a request to the search application, as demonstrated by a cross-site request forgery (CSRF) attack, aka SPL-45172.

Published Jan 3, 2012 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2011-4622: The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and possibly other versions, does not prop...

The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and possibly other versions, does not properly handle when Programmable Interval Timer (PIT) interrupt requests (IRQs) when a virtual interrupt controller (irqchip) is not available, which allows local users to cause a denial of service (NULL pointer dereference) by starting a timer.

Published Jan 27, 2012 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2011-4608: mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to registe...

mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide malicious content, hijack sessions, and steal credentials by registering from an external vhost that does not enforce security constraints.

Published Jan 27, 2012 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2011-4361: MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allo...

MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.

Published Jan 8, 2012 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2011-4354: crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in...

crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.

Published Jan 27, 2012 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2011-4314: message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platfo...

message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

Published Jan 27, 2012 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2011-4153: PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote att...

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

Published Jan 18, 2012 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2011-4114: The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a dire...

The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.

Published Jan 13, 2012 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2011-4077: Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when...

Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when CONFIG_XFS_DEBUG is disabled, allows local users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an XFS image containing a symbolic link with a long pathname.

Published Jan 27, 2012 · Updated Aug 6, 2024