2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2011-5277Multiple SQL injection vulnerabilities in signature.php in the Advanced Forum Signatures (aka afsignatures) plugin 2.0.4...
CVE-2011-4958Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x...
CVE-2011-4573Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote a...
CVE-2011-3346Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest u...
CVE-2011-5276SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain T...
CVE-2011-5275The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc use...
CVE-2011-5274The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before...
CVE-2011-5273Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows r...
CVE-2011-5272SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execu...
CVE-2011-3199Multiple cross-site scripting (XSS) vulnerabilities in Domain Technologie Control (DTC) before 0.34.1 allow remote authe...
CVE-2011-3198Domain Technologie Control (DTC) before 0.34.1 includes a password in the -b command line argument to htpasswd, which mi...
CVE-2011-3197SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execu...
CVE-2011-3196The setup script in Domain Technologie Control (DTC) before 0.34.1 uses world-readable permissions for /etc/apache2/apac...
CVE-2011-3195shared/inc/sql/lists.php in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute ...
CVE-2011-3153dmrc.c in Light Display Manager (aka LightDM) before 1.1.1 allows local users to read arbitrary files via a symlink atta...
CVE-2011-4696Directory traversal vulnerability in Eye-Fi Helper before 3.4.23 allows man-in-the-middle attackers to create arbitrary ...
CVE-2011-3634methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Hos...
CVE-2011-4580Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remot...
CVE-2011-4111Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x...
CVE-2011-2941Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect...
CVE-2011-1749The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to appen...
CVE-2011-4083The sosreport utility in the Red Hat sos package before 1.7-9 and 2.x before 2.2-17 includes (1) Certificate-based Red H...
CVE-2011-3605The process_rs function in the router advertisement daemon (radvd) before 1.8.2, when UnicastOnly is enabled, allows rem...
CVE-2011-3604The process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attackers to cause a denia...
CVE-2011-3601Buffer overflow in the process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attacke...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now