- EPSS 0.61%
- Published 08.01.2012 11:55:18
- Last modified 11.04.2025 00:51:21
MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.
CVE-2011-3919
- EPSS 2.5%
- Published 07.01.2012 11:55:13
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
- EPSS 92.41%
- Published 25.12.2011 01:55:02
- Last modified 11.04.2025 00:51:21
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to exec...
- EPSS 5.56%
- Published 24.12.2011 19:55:05
- Last modified 11.04.2025 00:51:21
Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service (segmentation fault) via...
CVE-2011-4516
- EPSS 47.82%
- Published 15.12.2011 03:57:34
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding st...
CVE-2011-4517
- EPSS 42.13%
- Published 15.12.2011 03:57:34
- Last modified 11.04.2025 00:51:21
The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a deni...
- EPSS 1.33%
- Published 13.12.2011 21:55:01
- Last modified 11.04.2025 00:51:21
libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
- EPSS 32.27%
- Published 08.12.2011 11:55:02
- Last modified 11.04.2025 00:51:21
dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet.
CVE-2011-4566
- EPSS 55.85%
- Published 29.11.2011 00:55:01
- Last modified 11.04.2025 00:51:21
Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_v...
CVE-2011-4107
- EPSS 12.6%
- Published 17.11.2011 19:55:01
- Last modified 11.04.2025 00:51:21
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity ref...