2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

CVE IDSeverityCVSSDescription
CVE-2011-2156The SmarterTools SmarterStats 6.0 web server allows remote attackers to obtain directory listings via a direct request f...
CVE-2011-2155Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without...
CVE-2011-2154login.aspx in the SmarterTools SmarterStats 6.0 web server does not include the HTTPOnly flag in a Set-Cookie header for...
CVE-2011-2153Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in th...
CVE-2011-2152The SmarterTools SmarterStats 6.0 web server generates web pages containing external links in response to GET requests w...
CVE-2011-2151The (1) Admin/frmEmailReportSettings.aspx, (2) Admin/frmGeneralSettings.aspx, (3) Admin/frmSite.aspx, (4) Client/frmUser...
CVE-2011-2150The SmarterTools SmarterStats 6.0 web server does not properly validate string data that is intended for storage in an X...
CVE-2011-2149Multiple SQL injection vulnerabilities in the SmarterTools SmarterStats 6.0 web server allow remote attackers to execute...
CVE-2011-2148Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands...
CVE-2011-2147Openswan 2.2.x does not properly restrict permissions for (1) /var/run/starter.pid, related to starter.c in the IPsec st...
CVE-2011-2021Session fixation vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote...
CVE-2011-2020Cross-site scripting (XSS) vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 all...
CVE-2011-1838Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to ...
CVE-2011-1784The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalive...
CVE-2011-1582Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that hav...
CVE-2011-1327The Keystroke Encryption feature in Trend Micro Internet Security 2009 (aka Virus Buster 2009 and PC-cillin 2009) does n...
CVE-2011-0966Directory traversal vulnerability in cwhp/auditLog.do in the Homepage Auditing component in Cisco CiscoWorks Common Serv...
CVE-2011-0962Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Dev...
CVE-2011-0961Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Service...
CVE-2011-0960Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to e...
CVE-2011-0959Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote a...
CVE-2011-0723FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to cause a denial of service (application c...
CVE-2011-0722FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (heap m...
CVE-2011-2144The eDocument Conversion Actions implementation in IBM Datacap Taskmaster Capture 8.0.1 FP1 and earlier allows remote at...
CVE-2011-2143IBM Datacap Taskmaster Capture 8.0.1 before FP1, when Windows Authentication is enabled, allows remote attackers to obta...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now