2011 CVE Vulnerabilities
4,899 CVEs published in 2011.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-4518 | — | — | 26.4% | May 23, 2013 | Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remo... |
| CVE-2011-4609 | — | — | 1.8% | May 2, 2013 | The svc_run function in the RPC implementation in glibc before 2.15 allows remote attackers to cause a denial of service... |
| CVE-2011-4515 | — | — | 0.4% | Mar 21, 2013 | Siemens WinCC (TIA Portal) 11 uses a reversible algorithm for storing HMI web-application passwords in world-readable an... |
| CVE-2011-4966 | — | — | 1.4% | Mar 12, 2013 | modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not prop... |
| CVE-2011-1165 | — | — | 2.3% | Mar 12, 2013 | Vino, possibly before 3.2, does not properly document that it opens ports in UPnP routers when the "Configure network to... |
| CVE-2011-1164 | — | — | 1.6% | Mar 12, 2013 | Vino before 2.99.4 can connect external networks contrary to the statement in the vino-preferences dialog box, which mig... |
| CVE-2011-4969 | — | — | 19.2% | Mar 8, 2013 | Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows rem... |
| CVE-2011-2504 | — | — | 0.4% | Mar 8, 2013 | Untrusted search path vulnerability in x11perfcomp in XFree86 x11perf before 1.5.4 allows local users to gain privileges... |
| CVE-2011-3201 | — | — | 2.7% | Mar 8, 2013 | GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter ... |
| CVE-2011-4318 | — | — | 1.3% | Mar 7, 2013 | Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does ... |
| CVE-2011-4355 | — | — | 0.4% | Mar 5, 2013 | GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the cu... |
| CVE-2011-3638 | — | — | 0.4% | Mar 1, 2013 | fs/ext4/extents.c in the Linux kernel before 3.0 does not mark a modified extent as dirty in certain cases of extent spl... |
| CVE-2011-2905 | — | — | 0.4% | Mar 1, 2013 | Untrusted search path vulnerability in the perf_config function in tools/perf/util/config.c in perf, as distributed in t... |
| CVE-2011-2491 | — | — | 0.4% | Mar 1, 2013 | The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 al... |
| CVE-2011-1182 | — | — | 0.5% | Mar 1, 2013 | kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a s... |
| CVE-2011-1019 | — | — | 0.4% | Mar 1, 2013 | The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_S... |
| CVE-2011-5265 | — | — | 10.0% | Feb 12, 2013 | Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress ... |
| CVE-2011-5264 | — | — | 2.2% | Feb 12, 2013 | Cross-site scripting (XSS) vulnerability in lazyest-backup.php in the Lazyest Backup plugin before 0.2.2 for WordPress a... |
| CVE-2011-5263 | — | — | 1.3% | Feb 12, 2013 | Cross-site scripting (XSS) vulnerability in RetrieveMailExamples in SAP NetWeaver 7.30 and earlier allows remote attacke... |
| CVE-2011-5262 | — | — | 1.1% | Feb 12, 2013 | SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL comma... |
| CVE-2011-5261 | — | — | 3.6% | Feb 12, 2013 | Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and ... |
| CVE-2011-5260 | — | — | 1.2% | Feb 12, 2013 | Cross-site scripting (XSS) vulnerability in SAP/BW/DOC/METADATA in SAP NetWeaver allows remote attackers to inject arbit... |
| CVE-2011-5259 | — | — | 1.2% | Feb 12, 2013 | SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attacker... |
| CVE-2011-5258 | — | — | 2.1% | Feb 12, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.6.11.2 allow remote attackers to inject arbitr... |
| CVE-2011-5257 | — | — | 3.8% | Feb 12, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote att... |
Check if your code is affected by 2011 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now