2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

CVE IDSeverityCVSSDescription
CVE-2011-3147HIGH8.6Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciou...
CVE-2011-3145LOW3.8When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So...
CVE-2011-1830MEDIUM5.7Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so.
CVE-2011-0705——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2011-2767——mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file...
CVE-2011-2765——pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attack...
CVE-2011-4893——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2011-4892——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2011-4891——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2011-4183MEDIUM6.5A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE ...
CVE-2011-4182HIGH7.3Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to c...
CVE-2011-4181HIGH7.5A vulnerability in open build service allows remote attackers to gain access to source files even though source access i...
CVE-2011-4190MEDIUM5.9The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump pri...
CVE-2011-3172MEDIUM5.4A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disa...
CVE-2011-0467HIGH8.8A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows auth...
CVE-2011-0704——389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica cra...
CVE-2011-3178HIGH8.1In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used...
CVE-2011-3477——GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2...
CVE-2011-4973——Authentication bypass vulnerability in mod_nss 1.0.8 allows remote attackers to assume the identity of a valid user by u...
CVE-2011-4889——The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Serv...
CVE-2011-4069——html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequen...
CVE-2011-4068——The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authen...
CVE-2011-2902——zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes t...
CVE-2011-4955——Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress ...
CVE-2011-4334——edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated user...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now