LiveActive security incident?Get immediate response
CVE archive

June 2011

Browse CVE records published in June 2011, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 377 matching CVEs · Page 3 of 8.

Unknown · CVSS Not scored

CVE-2011-2477: Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in Icinga before 1.4.1, when...

Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in Icinga before 1.4.1, when escape_html_tags is disabled, allow remote attackers to inject arbitrary web script or HTML via a JavaScript expression, as demonstrated by the onload attribute of a BODY element located after a check-host-alive! sequence, a different vulnerability than CVE-2011-2179.

Published Jun 14, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-2395: The Neighbor Discovery (ND) protocol implementation in Cisco IOS on unspecified switches allows remote atta...

The Neighbor Discovery (ND) protocol implementation in Cisco IOS on unspecified switches allows remote attackers to bypass the Router Advertisement Guarding functionality via a fragmented IPv6 packet in which the Router Advertisement (RA) message is contained in the second fragment, as demonstrated by (1) a packet in which the first fragment contains a long Destination Options extension header or (2) a packet in which the first fragment contains an ICMPv6 Echo Request message.

Published Jun 7, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-2383: Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, whic...

Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing an http: URL that redirects to a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue, aka "Drag and Drop Information Disclosure Vulnerability." NOTE: this vulnerability exists because of an incomplete fix in the Internet Explorer 9 release.

Published Jun 3, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-2364: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbird befo...

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbird before 3.1.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2365.

Published Jun 30, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-2363: Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG ele...

Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.

Published Jun 30, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-2365: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbird befo...

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbird before 3.1.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-2364.

Published Jun 30, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-2329: The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 d...

The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration of timestamp tokens, which allows remote attackers to bypass intended access restrictions by leveraging an expired token, a different vulnerability than CVE-2011-0730.

Published Jun 2, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-2217: Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Fa...

Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.237, as used in VI Client (aka VMware Infrastructure Client) 2.0.2 before Build 230598 and 2.5 before Build 204931 in VMware Infrastructure 3, do not properly handle attempted initialization within Internet Explorer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HTML document.

Published Jun 6, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-2202: The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filename...

The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."

Published Jun 16, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-2193: Multiple buffer overflows in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager)...

Multiple buffer overflows in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.x before 2.4.14, 2.5.x before 2.5.6, and 3.x before 3.0.2 allow (1) remote authenticated users to gain privileges via a long Job_Name field in a qsub command to the server, and might allow (2) local users to gain privileges via vectors involving a long host variable in pbs_iff.

Published Jun 24, 2011 · Updated Aug 6, 2024