NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11320 | CVE-2011-5060 | The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program, a different vulnerability in a different package than CVE-2011-4114. | 2 | 3.3 | Low | 2017-01-07 | 2012-01-30 | View | |
| 11319 | CVE-2011-5059 | Stack-based buffer overflow in Final Draft 8 before 8.02 allows remote attackers to execute arbitrary code via a crafted SmartType element, a different vulnerability than CVE-2011-5002. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 10 | High | 2017-01-07 | 2012-01-13 | View | |
| 11318 | CVE-2011-5058 | The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the web root by specifying a non-existent directory using (backslash) characters in an HTTP GET request. | 2 | 6.4 | Medium | 2017-01-07 | 2012-11-27 | View | |
| 11317 | CVE-2011-5057 | Apache Struts 2.3.1.1 and earlier provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor." | 2 | 5 | Medium | 2017-01-07 | 2012-01-09 | View | |
| 11316 | CVE-2011-5056 | The authoritative server in MaraDNS through 2.0.04 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which might allow local users to cause a denial of service (CPU consumption) via crafted records in zone files, a different vulnerability than CVE-2012-0024. | 2 | 2.1 | Low | 2017-01-07 | 2012-01-17 | View |
Page 15409 of 17672, showing 5 records out of 88360 total, starting on record 77041, ending on 77045