Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2011-08-10 CVE-2011-2136 Numeric Errors vulnerability in Adobe AIR and Flash Player
Integer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2138 and CVE-2011-2416.
network
low complexity
adobe apple linux microsoft sun google CWE-189
critical
10.0
2011-08-10 CVE-2011-2135 Buffer Errors vulnerability in Adobe AIR and Flash Player
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2140, CVE-2011-2417, and CVE-2011-2425.
network
low complexity
adobe apple linux microsoft sun google CWE-119
critical
10.0
2011-08-10 CVE-2011-3130 Unspecified vulnerability in Wordpress
wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Taxonomy query hardening," possibly involving SQL injection.
network
low complexity
wordpress
7.5
2011-08-10 CVE-2011-3129 Permissions, Privileges, and Access Controls vulnerability in Wordpress
The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.
network
wordpress CWE-264
critical
9.3
2011-08-10 CVE-2011-3128 Information Exposure vulnerability in Wordpress
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php.
network
low complexity
wordpress CWE-200
5.0
2011-08-10 CVE-2011-3127 Improper Input Validation vulnerability in Wordpress
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 does not prevent rendering for (1) admin or (2) login pages inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
network
wordpress CWE-20
5.8
2011-08-10 CVE-2011-3126 Information Exposure vulnerability in Wordpress
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.
network
low complexity
wordpress CWE-200
5.0
2011-08-10 CVE-2011-3125 Unspecified vulnerability in Wordpress
Unspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hardening."
network
low complexity
wordpress
critical
10.0
2011-08-10 CVE-2011-2137 Buffer Errors vulnerability in Adobe AIR and Flash Player
Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2130, CVE-2011-2134, CVE-2011-2414, and CVE-2011-2415.
network
low complexity
adobe apple linux microsoft sun google CWE-119
critical
10.0
2011-08-10 CVE-2011-2134 Buffer Errors vulnerability in Adobe AIR and Flash Player
Buffer overflow in Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2130, CVE-2011-2137, CVE-2011-2414, and CVE-2011-2415.
network
low complexity
adobe apple linux microsoft sun google CWE-119
critical
10.0