LiveActive security incident?Get immediate response
CVE archive

October 2011

Browse CVE records published in October 2011, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 443 matching CVEs · Page 7 of 9.

Unknown · CVSS Not scored

CVE-2011-3227: libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstand...

libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.

Published Oct 14, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-3213: The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certi...

The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for an initial https WebDAV connection, which allows man-in-the-middle attackers to hijack WebDAV communication by presenting an arbitrary certificate for a subsequent connection.

Published Oct 14, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-2894: Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and poss...

Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrusted code by (1) serializing a java.lang.Proxy instance and using InvocationHandler, or (2) accessing internal AOP interfaces, as demonstrated using deserialization of a DefaultListableBeanFactory instance to execute arbitrary commands via the java.lang.Runtime class.

Published Oct 4, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-2702: Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIM...

Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allows context-dependent attackers to execute arbitrary code via a negative length parameter to (1) memcpy-ssse3-rep.S, (2) memcpy-ssse3.S, or (3) memset-sse2.S in sysdeps/i386/i686/multiarch/, which triggers an out-of-bounds read, as demonstrated using the memcpy function.

Published Oct 27, 2014 · Updated Aug 6, 2024