CVE-2011-1934: lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1.
lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1.
Published Nov 26, 2019 · Updated Aug 6, 2024
Browse CVE records published in November 2011, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 32 of 332 matching CVEs · Page 7 of 7.
lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1.
Published Nov 26, 2019 · Updated Aug 6, 2024
In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.
Published Nov 14, 2019 · Updated Aug 6, 2024
SQL injection vulnerability in Jifty::DBI before 0.68.
Published Nov 26, 2019 · Updated Aug 6, 2024
An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying to access a removed smil element.
Published Nov 12, 2019 · Updated Aug 6, 2024
WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption).
Published Nov 12, 2019 · Updated Aug 6, 2024
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
Published Nov 14, 2019 · Updated Aug 6, 2024
Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.
Published Nov 4, 2011 · Updated Aug 6, 2024
The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of osascript to send Apple events to the launchd daemon, a related issue to CVE-2008-7303.
Published Nov 15, 2011 · Updated Aug 6, 2024
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service via a sequence of repeated log messages sent within short periods of time.
Published Nov 14, 2019 · Updated Aug 6, 2024
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset.
Published Nov 14, 2019 · Updated Aug 6, 2024
WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.
Published Nov 5, 2019 · Updated Aug 6, 2024
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset
Published Nov 14, 2019 · Updated Aug 6, 2024
The WebKit::WebPluginContainerImpl::handleEvent function in Google Chrome before Blink M11 allows an attacker to cause a denial of service (crash) via the htmlpluginelement.cpp plugin.
Published Nov 5, 2019 · Updated Aug 6, 2024
Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (STMM) feature and the AUTOMATIC DATABASE_MEMORY setting are configured, allows local users to cause a denial of service (daemon crash) via unknown vectors.
Published Nov 9, 2011 · Updated Aug 6, 2024
IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.
Published Nov 26, 2011 · Updated Aug 6, 2024
Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted REGION record in a PICT file.
Published Nov 9, 2012 · Updated Aug 6, 2024
IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, which allows local users to cause a denial of service (system crash) via a crafted call.
Published Nov 11, 2011 · Updated Aug 6, 2024
The Web User Interface on the IBM TS3100 and TS3200 tape libraries with firmware before A.60 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.
Published Nov 28, 2011 · Updated Aug 6, 2024
An Integer Overflow exists in WebKit in Google Chrome before Blink M11 in the macOS WebCore::GraphicsContext::fillRect function.
Published Nov 6, 2019 · Updated Aug 6, 2024
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.
Published Nov 5, 2019 · Updated Aug 6, 2024
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
Published Nov 14, 2019 · Updated Aug 6, 2024
In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.
Published Nov 14, 2019 · Updated Aug 6, 2024
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php.
Published Nov 5, 2019 · Updated Aug 6, 2024
v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mode and potentially other consequences.
Published Nov 14, 2019 · Updated Aug 6, 2024
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/ImageManager/manager.php.
Published Nov 5, 2019 · Updated Aug 6, 2024
The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other products, when using block ciphers in cipher-block chaining (CBC) mode, allows remote attackers to obtain plaintext data via a chosen-ciphertext attack on SOAP responses, aka "character encoding pattern attack."
Published Nov 23, 2012 · Updated Aug 6, 2024
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
Published Nov 20, 2019 · Updated Aug 6, 2024
Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1), and Cisco IOS 12.4 and 15.1, allows remote attackers to cause a denial of service (memory consumption and process failure or device reload) via a malformed SIP message, aka Bug IDs CSCti75128 and CSCtj09179.
Published Nov 1, 2011 · Updated Aug 6, 2024
In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 session.
Published Nov 15, 2019 · Updated Aug 6, 2024
Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.
Published Nov 20, 2019 · Updated Aug 6, 2024
phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.
Published Nov 13, 2019 · Updated Aug 6, 2024
Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.
Published Nov 19, 2012 · Updated Aug 6, 2024