2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

CVE IDSeverityCVSSDescription
CVE-2011-3147HIGH8.6Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciou...
CVE-2011-3145LOW3.8When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So...
CVE-2011-1830MEDIUM5.7Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so.
CVE-2011-0705Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2011-2767mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file...
CVE-2011-2765pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attack...
CVE-2011-4893Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2011-4892Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2011-4891Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2011-4183MEDIUM6.5A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE ...
CVE-2011-4182HIGH7.3Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to c...
CVE-2011-4181HIGH7.5A vulnerability in open build service allows remote attackers to gain access to source files even though source access i...
CVE-2011-4190MEDIUM5.9The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump pri...
CVE-2011-3172MEDIUM5.4A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disa...
CVE-2011-0467HIGH8.8A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows auth...
CVE-2011-0704389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica cra...
CVE-2011-3178HIGH8.1In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used...
CVE-2011-3477GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2...
CVE-2011-4973Authentication bypass vulnerability in mod_nss 1.0.8 allows remote attackers to assume the identity of a valid user by u...
CVE-2011-4889The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Serv...
CVE-2011-4069html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequen...
CVE-2011-4068The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authen...
CVE-2011-2902zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes t...
CVE-2011-4955Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress ...
CVE-2011-4334edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated user...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now