CVE-2011-2522
- EPSS 18.2%
- Veröffentlicht 29.07.2011 20:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start...
CVE-2011-2694
- EPSS 3.13%
- Veröffentlicht 29.07.2011 20:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the usernam...
CVE-2011-2688
- EPSS 6.71%
- Veröffentlicht 28.07.2011 18:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the user field.
CVE-2011-2501
- EPSS 2.25%
- Veröffentlicht 17.07.2011 20:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers...
CVE-2011-2690
- EPSS 1.26%
- Veröffentlicht 17.07.2011 20:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, allows remote attackers to overwr...
CVE-2011-2691
- EPSS 7.69%
- Veröffentlicht 17.07.2011 20:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote attackers t...
CVE-2011-2692
- EPSS 7.47%
- Veröffentlicht 17.07.2011 20:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory...
CVE-2011-1526
- EPSS 0.32%
- Veröffentlicht 11.07.2011 20:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, ...
CVE-2011-2192
- EPSS 2.05%
- Veröffentlicht 07.07.2011 21:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSS...
- EPSS 22.71%
- Veröffentlicht 06.06.2011 19:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as e...