CVE-2011-1755
- EPSS 8.46%
- Veröffentlicht 21.06.2011 02:52:43
- Zuletzt bearbeitet 11.04.2025 00:51:21
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity reference...
CVE-2011-1943
- EPSS 0.04%
- Veröffentlicht 14.06.2011 17:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive information by read...
- EPSS 22.71%
- Veröffentlicht 06.06.2011 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as e...
CVE-2011-1783
- EPSS 11.09%
- Veröffentlicht 06.06.2011 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memor...
- EPSS 5.19%
- Veröffentlicht 20.03.2011 02:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a string composed of a % (percent) character followed by invalid hex characte...
- EPSS 45.28%
- Veröffentlicht 02.03.2011 20:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions...
- EPSS 71.38%
- Veröffentlicht 22.02.2011 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect f...
CVE-2010-4743
- EPSS 4.08%
- Veröffentlicht 18.02.2011 19:00:14
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow remote attackers to execute arbitrary code via a crafted ABC file, a different vulnerability than CVE-2010-3441. NOTE: some of these details are obt...
- EPSS 1.5%
- Veröffentlicht 18.02.2011 19:00:14
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impact and attack vectors, a different issue than CVE-2010-3441.
CVE-2010-3441
- EPSS 5.82%
- Veröffentlicht 18.02.2011 17:00:34
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to the PUT0 and PUT1 output macros; (2) a crafted input file, related to the trim_title function; and poss...