Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2011-05-31 CVE-2011-1938 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in PHP
Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket.
network
low complexity
php CWE-119
7.5
2011-05-31 CVE-2011-1937 Cross-Site Scripting vulnerability in Webmin
Cross-site scripting (XSS) vulnerability in Webmin 1.540 and earlier allows local users to inject arbitrary web script or HTML via a chfn command that changes the real (aka Full Name) field, related to useradmin/index.cgi and useradmin/user-lib.pl.
network
webmin CWE-79
4.3
2011-05-31 CVE-2011-1922 Resource Management Errors vulnerability in Nlnetlabs Unbound
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.
network
nlnetlabs CWE-399
4.3
2011-05-31 CVE-2011-1910 Numeric Errors vulnerability in ISC Bind
Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.
network
low complexity
isc CWE-189
5.0
2011-05-31 CVE-2011-1651 Resource Management Errors vulnerability in Cisco IOS XR
Cisco IOS XR 3.9.x and 4.0.x before 4.0.3 and 4.1.x before 4.1.1, when an SPA interface processor is installed, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 packet, aka Bug ID CSCto45095.
network
low complexity
cisco CWE-399
7.8
2011-05-31 CVE-2011-1649 Resource Management Errors vulnerability in Cisco products
The Internet Streamer application in Cisco Content Delivery System (CDS) with software 2.5.7, 2.5.8, and 2.5.9 before build 126 allows remote attackers to cause a denial of service (Web Engine crash) via a crafted URL, aka Bug IDs CSCtg67333 and CSCth25341.
network
low complexity
cisco CWE-399
7.8
2011-05-31 CVE-2011-1647 Information Exposure vulnerability in Cisco products
The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote attackers to read the private key for the admin SSL certificate via unspecified vectors, aka Bug ID CSCtn23871.
network
low complexity
cisco CWE-200
5.0
2011-05-31 CVE-2011-1646 Code Injection vulnerability in Cisco products
The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote authenticated users to execute arbitrary commands via the (1) ping test parameter or (2) traceroute test parameter, aka Bug ID CSCtn23871.
network
low complexity
cisco CWE-94
critical
9.0
2011-05-31 CVE-2011-1645 Configuration vulnerability in Cisco products
The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote attackers to read the backup configuration file, and consequently execute arbitrary code, via unspecified vectors, aka Bug ID CSCtn23871.
network
cisco CWE-16
critical
9.3
2011-05-31 CVE-2011-1512 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a malformed BIFF record in a .xls Excel spreadsheet attachment, aka SPR PRAD8E3HKR.
network
autonomy ibm CWE-119
critical
9.3