Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2011-05-13 CVE-2011-1248 Improper Input Validation vulnerability in Microsoft Windows Server 2003 and Windows Server 2008
WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."
network
microsoft CWE-20
critical
9.3
2011-05-13 CVE-2011-0341 Buffer Errors vulnerability in Artifex Mupdf 2008.09.02
Stack-based buffer overflow in the pdfmoz_onmouse function in apps/mozilla/moz_main.c in the MuPDF plug-in 2008.09.02 for Firefox allows remote attackers to execute arbitrary code via a crafted web site.
network
artifex mozilla CWE-119
critical
9.3
2011-05-10 CVE-2011-2075 Remote Code Execution vulnerability in Google Chrome 11.0.696.65/12.0.742.30
Unspecified vulnerability in Google Chrome 11.0.696.65 on Windows 7 SP1 allows remote attackers to execute arbitrary code via unknown vectors.
network
google microsoft
critical
9.3
2011-05-07 CVE-2011-1735 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in HP Openview Storage Data Protector 6.00/6.10/6.11
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed bm message.
network
low complexity
hp CWE-119
critical
10.0
2011-05-07 CVE-2011-1734 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in HP Openview Storage Data Protector 6.00/6.10/6.11
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed omniiaputil message.
network
low complexity
hp CWE-119
critical
10.0
2011-05-07 CVE-2011-1733 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in HP Openview Storage Data Protector 6.00/6.10/6.11
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed HPFGConfig message.
network
low complexity
hp CWE-119
critical
10.0
2011-05-07 CVE-2011-1732 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in HP Openview Storage Data Protector 6.00/6.10/6.11
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed stutil message.
network
low complexity
hp CWE-119
critical
10.0
2011-05-07 CVE-2011-1731 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in HP Openview Storage Data Protector 6.00/6.10/6.11
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed EXEC_INTEGUTIL message.
network
low complexity
hp CWE-119
critical
10.0
2011-05-07 CVE-2011-1730 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in HP Openview Storage Data Protector 6.00/6.10/6.11
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed EXEC_SCRIPT message.
network
low complexity
hp CWE-119
critical
10.0
2011-05-07 CVE-2011-1729 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in HP Openview Storage Data Protector 6.00/6.10/6.11
Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed GET_FILE message.
network
low complexity
hp CWE-119
critical
10.0