CVE-2011-2691
- EPSS 7.69%
- Veröffentlicht 17.07.2011 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote attackers t...
CVE-2011-2692
- EPSS 7.47%
- Veröffentlicht 17.07.2011 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory...
CVE-2011-1526
- EPSS 0.32%
- Veröffentlicht 11.07.2011 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, ...
CVE-2011-2192
- EPSS 2.05%
- Veröffentlicht 07.07.2011 21:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSS...
- EPSS 22.71%
- Veröffentlicht 06.06.2011 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as e...
CVE-2011-1783
- EPSS 11.09%
- Veröffentlicht 06.06.2011 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memor...
CVE-2011-1799
- EPSS 0.61%
- Veröffentlicht 16.05.2011 17:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Google Chrome before 11.0.696.68 does not properly perform casts of variables during interaction with the WebKit engine, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVE-2011-0419
- EPSS 54.11%
- Veröffentlicht 16.05.2011 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac...
CVE-2011-1440
- EPSS 2.48%
- Veröffentlicht 03.05.2011 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the ruby element and Cascading Style Sheets (CSS) token sequences.
CVE-2011-1444
- EPSS 0.69%
- Veröffentlicht 03.05.2011 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Race condition in the sandbox launcher implementation in Google Chrome before 11.0.696.57 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.