LiveActive security incident?Get immediate response
CVE archive

March 2011

Browse CVE records published in March 2011, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 388 matching CVEs · Page 5 of 8.

Unknown · CVSS Not scored

CVE-2011-1176: The configuration merger in itk.c in the Steinar H.

The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which might allow remote attackers to gain privileges by leveraging the root uid and root gid of an mpm-itk process.

Published Mar 29, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1073: crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arb...

crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum comparisons on arbitrary pairs of files via two symlink attacks on /tmp/crontab.XXXXXXXXXX temporary files.

Published Mar 4, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1146: libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connecti...

libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.

Published Mar 15, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1099: Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls before 1.0.2 allow remote attack...

Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls before 1.0.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the p parameter in a preview action to index.php, or (2) delete arbitrary files via a .. (dot dot) in the p parameter in a delete action to index.php.

Published Mar 9, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1153: Multiple format string vulnerabilities in phar_object.c in the phar extension in PHP 5.3.5 and earlier allo...

Multiple format string vulnerabilities in phar_object.c in the phar extension in PHP 5.3.5 and earlier allow context-dependent attackers to obtain sensitive information from process memory, cause a denial of service (memory corruption), or possibly execute arbitrary code via format string specifiers in an argument to a class method, leading to an incorrect zend_throw_exception_ex call.

Published Mar 16, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1144: The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a symlink attac...

The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1072.

Published Mar 3, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1147: Multiple stack-based and heap-based buffer overflows in the (1) decode_open_type and (2) udptl_rx_packet fu...

Multiple stack-based and heap-based buffer overflows in the (1) decode_open_type and (2) udptl_rx_packet functions in main/udptl.c in Asterisk Open Source 1.4.x before 1.4.39.2, 1.6.1.x before 1.6.1.22, 1.6.2.x before 1.6.2.16.2, and 1.8 before 1.8.2.4; Business Edition C.x.x before C.3.6.3; AsteriskNOW 1.5; and s800i (Asterisk Appliance), when T.38 support is enabled, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UDPTL packet.

Published Mar 15, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1140: Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string f...

Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet.

Published Mar 3, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1155: The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attacke...

The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

Published Mar 30, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1094: kio/kio/tcpslavebase.cpp in KDE KSSL in kdelibs before 4.6.1 does not properly verify that the server hostn...

kio/kio/tcpslavebase.cpp in KDE KSSL in kdelibs before 4.6.1 does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a certificate issued by a legitimate Certification Authority for an IP address, a different vulnerability than CVE-2009-2702.

Published Mar 16, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1091: libymsg.c in the Yahoo!

libymsg.c in the Yahoo! protocol plugin in libpurple in Pidgin 2.6.0 through 2.7.10 allows (1) remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG notification packet, and allows (2) remote Yahoo! servers to cause a denial of service (NULL pointer dereference and application crash) via a malformed YMSG SMS message.

Published Mar 14, 2011 · Updated Aug 6, 2024