LiveActive security incident?Get immediate response
CVE archive

November 2011

Browse CVE records published in November 2011, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 32 of 332 matching CVEs · Page 7 of 7.

Unknown · CVSS Not scored

CVE-2011-1516: The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x...

The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of osascript to send Apple events to the launchd daemon, a related issue to CVE-2008-7303.

Published Nov 15, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1488: A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $R...

A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service via a sequence of repeated log messages sent within short periods of time.

Published Nov 14, 2019 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1489: A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when m...

A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset.

Published Nov 14, 2019 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1490: A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when mu...

A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset

Published Nov 14, 2019 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-1096: The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise...

The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other products, when using block ciphers in cipher-block chaining (CBC) mode, allows remote attackers to obtain plaintext data via a chosen-ciphertext attack on SOAP responses, aka "character encoding pattern attack."

Published Nov 23, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0941: Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x...

Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1), and Cisco IOS 12.4 and 15.1, allows remote attackers to cause a denial of service (memory consumption and process failure or device reload) via a malformed SIP message, aka Bug IDs CSCti75128 and CSCtj09179.

Published Nov 1, 2011 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-0433: Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME...

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.

Published Nov 19, 2012 · Updated Aug 6, 2024