Show filters
425 Total Results
Displaying 361-370 of 425
Sort by:
Attacker Value
Unknown

CVE-2011-3919

Disclosure Date: January 07, 2012 (last updated October 04, 2023)
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2011-3905

Disclosure Date: December 13, 2011 (last updated October 04, 2023)
libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-2834

Disclosure Date: September 19, 2011 (last updated October 04, 2023)
Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
0
Attacker Value
Unknown

CVE-2011-3389

Disclosure Date: September 06, 2011 (last updated October 04, 2023)
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
0
Attacker Value
Unknown

CVE-2011-1776

Disclosure Date: September 06, 2011 (last updated October 04, 2023)
The is_gpt_valid function in fs/partitions/efi.c in the Linux kernel before 2.6.39 does not check the size of an Extensible Firmware Interface (EFI) GUID Partition Table (GPT) entry, which allows physically proximate attackers to cause a denial of service (heap-based buffer overflow and OOPS) or obtain sensitive information from kernel heap memory by connecting a crafted GPT storage device, a different vulnerability than CVE-2011-1577.
Attacker Value
Unknown

CVE-2011-2213

Disclosure Date: August 29, 2011 (last updated October 04, 2023)
The inet_diag_bc_audit function in net/ipv4/inet_diag.c in the Linux kernel before 2.6.39.3 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message, as demonstrated by an INET_DIAG_BC_JMP instruction with a zero yes value, a different vulnerability than CVE-2010-3880.
0
Attacker Value
Unknown

CVE-2011-2821

Disclosure Date: August 29, 2011 (last updated October 04, 2023)
Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
0
Attacker Value
Unknown

CVE-2011-2492

Disclosure Date: July 28, 2011 (last updated October 04, 2023)
The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to (1) the l2cap_sock_getsockopt_old function in net/bluetooth/l2cap_sock.c and (2) the rfcomm_sock_getsockopt_old function in net/bluetooth/rfcomm/sock.c.
0
Attacker Value
Unknown

CVE-2011-2689

Disclosure Date: July 28, 2011 (last updated October 04, 2023)
The gfs2_fallocate function in fs/gfs2/file.c in the Linux kernel before 3.0-rc1 does not ensure that the size of a chunk allocation is a multiple of the block size, which allows local users to cause a denial of service (BUG and system crash) by arranging for all resource groups to have too little free space.
0
Attacker Value
Unknown

CVE-2011-1093

Disclosure Date: July 18, 2011 (last updated October 04, 2023)
The dccp_rcv_state_process function in net/dccp/input.c in the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel before 2.6.38 does not properly handle packets for a CLOSED endpoint, which allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending a DCCP-Close packet followed by a DCCP-Reset packet.
0