Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2011-07-17 CVE-2011-2758 Improper Authentication vulnerability in IBM Tivoli Directory Server
IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for access to LDAP Server log files, which allows remote attackers to obtain sensitive information via a crafted URL.
network
low complexity
ibm CWE-287
5.0
2011-07-17 CVE-2011-2757 Path Traversal vulnerability in Manageengine Servicedesk Plus 7.0.0/7.6/8.0
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary files via a ..
network
low complexity
manageengine CWE-22
5.0
2011-07-17 CVE-2011-2756 Improper Authentication vulnerability in Manageengine Servicedesk Plus 8.0
FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors.
network
low complexity
manageengine CWE-287
5.0
2011-07-17 CVE-2011-2755 Path Traversal vulnerability in Manageengine Servicedesk Plus 8.0
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
manageengine CWE-22
5.0
2011-07-17 CVE-2011-2754 Cross-Site Scripting vulnerability in IBM web Content Manager and Websphere Portal
Cross-site scripting (XSS) vulnerability in the PageBuilder2 (aka Page Builder) theme in IBM WebSphere Portal 7.x before 7.0.0.1 CF006, as used in IBM Web Content Manager (WCM) and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
4.3
2011-07-17 CVE-2011-2753 Cross-Site Request Forgery (CSRF) vulnerability in Squirrelmail
Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of unspecified victims via vectors involving (1) the empty trash implementation and (2) the Index Order (aka options_order) page, a different issue than CVE-2010-4555.
6.8
2011-07-17 CVE-2011-2752 Code Injection vulnerability in Squirrelmail
CRLF injection vulnerability in SquirrelMail 1.4.21 and earlier allows remote attackers to modify or add preference values via a \n (newline) character, a different vulnerability than CVE-2010-4555.
5.8
2011-07-17 CVE-2011-2750 Resource Management Errors vulnerability in Novell File Reporter 1.0.1/1.0.1.1/1.0.2
NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.
network
low complexity
novell CWE-399
5.0
2011-07-17 CVE-2011-2691 NULL Pointer Dereference vulnerability in multiple products
The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote attackers to cause a denial of service (application crash) via a crafted PNG image.
network
low complexity
libpng fedoraproject debian CWE-476
6.5
2011-07-17 CVE-2011-2690 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, allows remote attackers to overwrite memory with an arbitrary amount of data, and possibly have unspecified other impact, via a crafted PNG image.
6.8