- EPSS 26.92%
- Veröffentlicht 08.12.2011 11:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet.
CVE-2011-4566
- EPSS 37.1%
- Veröffentlicht 29.11.2011 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_v...
CVE-2011-4107
- EPSS 12.43%
- Veröffentlicht 17.11.2011 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity ref...
CVE-2011-3892
- EPSS 2.11%
- Veröffentlicht 11.11.2011 11:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
CVE-2011-3895
- EPSS 3.44%
- Veröffentlicht 11.11.2011 11:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
CVE-2011-2189
- EPSS 7.62%
- Veröffentlicht 10.10.2011 10:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via reque...
CVE-2011-2766
- EPSS 0.26%
- Veröffentlicht 23.09.2011 10:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers.
CVE-2011-2834
- EPSS 2.9%
- Veröffentlicht 19.09.2011 12:02:55
- Zuletzt bearbeitet 11.04.2025 00:51:21
Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
CVE-2011-3389
- EPSS 3.93%
- Veröffentlicht 06.09.2011 19:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man...
CVE-2011-2821
- EPSS 1.92%
- Veröffentlicht 29.08.2011 15:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.