Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2011-06-14 CVE-2011-1861 Multiple vulnerability in HP Service Manager and Service Center
Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to modify data or obtain sensitive information via unknown vectors.
network
hp
8.3
2011-06-14 CVE-2011-1860 Multiple vulnerability in HP Service Manager and Service Center
Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to capture HTTP session credentials via unknown vectors.
network
low complexity
hp
5.0
2011-06-14 CVE-2011-1859 Multiple vulnerability in HP Service Manager and Service Center
Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote attackers to obtain sensitive information via unknown vectors.
network
low complexity
hp
5.0
2011-06-14 CVE-2011-1858 Multiple vulnerability in HP Service Manager and Service Center
Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows local users to bypass intended access restrictions via unknown vectors.
local
low complexity
hp
4.3
2011-06-14 CVE-2011-1857 Multiple vulnerability in HP Service Manager and Service Center
Unspecified vulnerability in HP Service Manager 7.02, 7.11, 9.20, and 9.21 and Service Center 6.2.8 allows remote authenticated users to bypass intended access restrictions via unknown vectors.
network
hp
8.2
2011-06-14 CVE-2011-1709 Permissions, Privileges, and Access Controls vulnerability in Gnome GDM
GNOME Display Manager (gdm) before 2.32.2, when glib 2.28 is used, enables execution of a web browser with the uid of the gdm account, which allows local users to gain privileges via vectors involving the x-scheme-handler/http MIME type.
local
low complexity
gnome CWE-264
7.2
2011-06-09 CVE-2011-2475 USE of Externally-Controlled Format String vulnerability in Sybase Onebridge Mobile Data Suite 5.5/5.6
Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybase OneBridge Mobile Data Suite 5.5 and 5.6 allows remote attackers to execute arbitrary code via format string specifiers in unspecified string fields, related to authentication logging.
network
low complexity
sybase CWE-134
critical
10.0
2011-06-09 CVE-2011-2474 Path Traversal vulnerability in Sybase Easerver 6.3.1
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path.
network
low complexity
sybase CWE-22
5.0
2011-06-09 CVE-2011-2473 Link Following vulnerability in Maynard Johnson Oprofile
The do_dump_data function in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to create or overwrite arbitrary files via a crafted --session-dir argument in conjunction with a symlink attack on the opd_pipe file, a different vulnerability than CVE-2011-1760.
6.3
2011-06-09 CVE-2011-2472 Path Traversal vulnerability in Maynard Johnson Oprofile
Directory traversal vulnerability in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to overwrite arbitrary files via a ..
6.3