Total
5231 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-4925 | 2 Cluster Resources, Clusterresources | 2 Torque Resource Manager, Torque Resource Manager | 2024-11-21 | 4.9 MEDIUM | N/A |
Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors. | |||||
CVE-2011-4867 | 2 Android, Tencent | 2 Android, Qqpphoto | 2024-11-21 | 5.8 MEDIUM | N/A |
The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a password hash via a crafted application. | |||||
CVE-2011-4865 | 2 Google, Tencent | 3 Android, Microblogpad, Wblog | 2024-11-21 | 5.8 MEDIUM | N/A |
The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attackers to read or modify message drafts and search keywords via a crafted application. | |||||
CVE-2011-4864 | 2 Google, Tencent | 2 Android, Mobileqq | 2024-11-21 | 5.8 MEDIUM | N/A |
The Tencent MobileQQ (com.tencent.mobileqq) application 2.2 for Android does not properly protect data, which allows remote attackers to read or modify messages and a friends list via a crafted application. | |||||
CVE-2011-4863 | 2 Google, Tencent | 2 Android, Qqpimsecure | 2024-11-21 | 5.8 MEDIUM | N/A |
The Tencent QQPimSecure (com.tencent.qqpimsecure) application 3.0.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS/MMS messages and a contact list via a crafted application. | |||||
CVE-2011-4861 | 1 Schneider-electric | 3 Quantum Ethernet Module 140noe77100, Quantum Ethernet Module 140noe77101, Quantum Ethernet Module 140noe77111 | 2024-11-21 | 10.0 HIGH | N/A |
The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows remote attackers to install arbitrary firmware updates via a MODBUS 125 function code to TCP port 502. | |||||
CVE-2011-4834 | 3 Hp, Ibm, Sun | 4 Application Lifestyle Management, Hp-ux, Aix and 1 more | 2024-11-21 | 4.6 MEDIUM | N/A |
The GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-UX, and Solaris allows local users to gain privileges via (1) a Trojan horse /tmp/tmp.txt FIFO or (2) a symlink attack on /tmp/tmp.txt. | |||||
CVE-2011-4773 | 2 Android, Anguanjia | 2 Android, Anguanjia | 2024-11-21 | 5.8 MEDIUM | N/A |
The AnGuanJia (com.anguanjia.safe) application 2.10.343 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application. | |||||
CVE-2011-4772 | 2 360, Android | 2 Kouxin, Android | 2024-11-21 | 5.8 MEDIUM | N/A |
The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application. | |||||
CVE-2011-4771 | 2 Android, Lucion | 2 Android, Scan To Pdf Free | 2024-11-21 | 5.8 MEDIUM | N/A |
The Scan to PDF Free (com.scan.to.pdf.trial) application 2.0.4 for Android does not properly protect data, which allows remote attackers to read or modify scanned files and a Google account via a crafted application. | |||||
CVE-2011-4770 | 2 Android, Qiwi | 2 Android, Wallet | 2024-11-21 | 5.8 MEDIUM | N/A |
The QIWI Wallet (ru.mw) application before 1.14.2 for Android does not properly protect data, which allows remote attackers to read or modify financial information via a crafted application. | |||||
CVE-2011-4769 | 2 360, Android | 2 Mobilesafe, Android | 2024-11-21 | 5.8 MEDIUM | N/A |
The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application. | |||||
CVE-2011-4718 | 1 Php | 1 Php | 2024-11-21 | 6.8 MEDIUM | N/A |
Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID. | |||||
CVE-2011-4705 | 2 Android, Ming | 2 Android, Blacklist Free | 2024-11-21 | 5.8 MEDIUM | N/A |
The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attackers to read or modify blacklists and a contact list via a crafted application that launches a "data-flow attack." | |||||
CVE-2011-4704 | 2 Android, Voxofon | 2 Android, Voxofon | 2024-11-21 | 5.8 MEDIUM | N/A |
The Voxofon (com.voxofon) application before 2.5.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS information via a crafted application. | |||||
CVE-2011-4703 | 2 Android, Nathanielkh | 2 Android, Limit My Call | 2024-11-21 | 5.8 MEDIUM | N/A |
The Limit My Call (com.limited.call.view) application 2.11 for Android does not properly protect data, which allows remote attackers to read or modify call logs and a contact list via a crafted application. | |||||
CVE-2011-4702 | 2 Android, Nimbuzz | 2 Android, Nimbuzz | 2024-11-21 | 5.8 MEDIUM | N/A |
The Nimbuzz (com.nimbuzz) application 2.0.8 and 2.0.10 for Android does not properly protect data, which allows remote attackers to read or modify a contact list via a crafted application. | |||||
CVE-2011-4701 | 2 Android, Hatena | 2 Android, Callconfirm | 2024-11-21 | 5.8 MEDIUM | N/A |
The CallConfirm (jp.gr.java_conf.ofnhwx.callconfirm) application 2.0.0 for Android does not properly protect data, which allows remote attackers to read or modify allow/block lists via a crafted application. | |||||
CVE-2011-4700 | 2 Android, Ubermedia | 2 Android, Ubersocial | 2024-11-21 | 5.8 MEDIUM | N/A |
The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application. | |||||
CVE-2011-4692 | 2 Apple, Google | 3 Safari, Webkit, Chrome | 2024-11-21 | 5.0 MEDIUM | N/A |
WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the browser cache via crafted JavaScript code, as demonstrated by visipisi. |