Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2011-05-07 CVE-2011-0070 Unspecified vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0069.
network
low complexity
mozilla
critical
10.0
2011-05-07 CVE-2011-0069 Unspecified vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0070.
network
low complexity
mozilla
critical
10.0
2011-05-07 CVE-2011-0066 Resource Management Errors vulnerability in Mozilla Firefox and Seamonkey
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mObserverList.
network
low complexity
mozilla CWE-399
critical
10.0
2011-05-07 CVE-2011-0065 Resource Management Errors vulnerability in Mozilla Firefox and Seamonkey
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel.
network
low complexity
mozilla CWE-399
critical
10.0
2011-05-04 CVE-2011-1900 Path Traversal vulnerability in Indusoft web Studio 6.1/7.0
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary code via an invalid request.
network
low complexity
indusoft CWE-22
critical
10.0
2011-05-04 CVE-2011-0340 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.
network
advantech indusoft CWE-119
critical
9.3
2011-05-03 CVE-2011-0610 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Acrobat and Acrobat Reader
The CoolType library in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
network
adobe microsoft apple CWE-119
critical
9.3
2011-05-03 CVE-2010-4803 Improper Input Validation vulnerability in Mojolicious
Mojolicious before 0.999927 does not properly implement HMAC-MD5 checksums, which has unspecified impact and remote attack vectors.
network
low complexity
mojolicious CWE-20
critical
10.0
2011-05-03 CVE-2010-4802 Improper Input Validation vulnerability in Mojolicious
Commands.pm in Mojolicious before 0.999928 does not properly perform CGI environment detection, which has unspecified impact and remote attack vectors.
network
low complexity
mojolicious CWE-20
critical
10.0
2011-05-03 CVE-2009-5074 Unspecified vulnerability in Mojolicious
Unspecified vulnerability in the MojoX::Dispatcher::Static implementation in Mojolicious before 0.991250 has unknown impact and attack vectors.
network
low complexity
mojolicious
critical
10.0