LiveActive security incident?Get immediate response
CVE archive

March 2011

Browse CVE records published in March 2011, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 388 matching CVEs · Page 6 of 8.

Unknown · CVSS Not scored

CVE-2011-1024: chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overla...

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

Published Mar 20, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1022: The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configura...

The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message.

Published Mar 22, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1006: Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group C...

Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 allows local users to gain privileges via a crafted controller list on the command line of an application. NOTE: it is not clear whether this issue crosses privilege boundaries.

Published Mar 22, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0759: Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration page in the Recaptcha (aka...

Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration page in the Recaptcha (aka WP-reCAPTCHA) plugin 2.9.8.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that disable the CAPTCHA requirement or insert cross-site scripting (XSS) sequences via the (1) recaptcha_opt_pubkey, (2) recaptcha_opt_privkey, (3) re_tabindex, (4) error_blank, (5) error_incorrect, (6) mailhide_pub, (7) mailhide_priv, (8) mh_replace_link, or (9) mh_replace_title parameter.

Published Mar 22, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0760: Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration screen in wp-relatedposts.p...

Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration screen in wp-relatedposts.php in the WP Related Posts plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences via the (1) wp_relatedposts_title, (2) wp_relatedposts_num, or (3) wp_relatedposts_type parameter.

Published Mar 28, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0745: SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a...

SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain duplicate check, which allows remote authenticated users to discover (1) the names of customers via a ShowDuplicates action to the Accounts module, reachable through index.php; or (2) the names of contact persons via a ShowDuplicates action to the Contacts module, reachable through index.php.

Published Mar 16, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0719: Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file...

Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.

Published Mar 1, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0695: Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in...

Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers are still running, which triggers an invalid pointer dereference.

Published Mar 15, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0700: Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated us...

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit title (aka post title or post_title), (2) post_status, (3) comment_status, (4) ping_status, and (5) escaping of tags within the tags meta box.

Published Mar 14, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0545: Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) be...

Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts, and possibly have unspecified other impact, via the userRole parameter.

Published Mar 28, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0421: The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not proper...

The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.

Published Mar 20, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0454: Buffer overflow in the PPP Access Concentrator (PPPAC) on the SEIL/x86 with firmware 1.00 through 1.61, SEI...

Buffer overflow in the PPP Access Concentrator (PPPAC) on the SEIL/x86 with firmware 1.00 through 1.61, SEIL/B1 with firmware 1.00 through 3.11, SEIL/X1 with firmware 1.00 through 3.11, SEIL/X2 with firmware 1.00 through 3.11, SEIL/Turbo with firmware 1.80 through 2.10, and SEIL/neu 2FE Plus with firmware 1.80 through 2.10 might allow remote attackers to execute arbitrary code via a PPPoE packet.

Published Mar 1, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0411: The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2....

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.

Published Mar 16, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0284: Double free vulnerability in the prepare_error_as function in do_as_req.c in the Key Distribution Center (K...

Double free vulnerability in the prepare_error_as function in do_as_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 through 1.9, when the PKINIT feature is enabled, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an e_data field containing typed data.

Published Mar 20, 2011 · Updated Aug 6, 2024