2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2011-4518Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remo...
CVE-2011-4609The svc_run function in the RPC implementation in glibc before 2.15 allows remote attackers to cause a denial of service...
CVE-2011-4515Siemens WinCC (TIA Portal) 11 uses a reversible algorithm for storing HMI web-application passwords in world-readable an...
CVE-2011-4966modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not prop...
CVE-2011-1165Vino, possibly before 3.2, does not properly document that it opens ports in UPnP routers when the "Configure network to...
CVE-2011-1164Vino before 2.99.4 can connect external networks contrary to the statement in the vino-preferences dialog box, which mig...
CVE-2011-4969Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows rem...
CVE-2011-2504Untrusted search path vulnerability in x11perfcomp in XFree86 x11perf before 1.5.4 allows local users to gain privileges...
CVE-2011-3201GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter ...
CVE-2011-4318Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does ...
CVE-2011-4355GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the cu...
CVE-2011-3638fs/ext4/extents.c in the Linux kernel before 3.0 does not mark a modified extent as dirty in certain cases of extent spl...
CVE-2011-2905Untrusted search path vulnerability in the perf_config function in tools/perf/util/config.c in perf, as distributed in t...
CVE-2011-2491The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 al...
CVE-2011-1182kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a s...
CVE-2011-1019The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_S...
CVE-2011-5265Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress ...
CVE-2011-5264Cross-site scripting (XSS) vulnerability in lazyest-backup.php in the Lazyest Backup plugin before 0.2.2 for WordPress a...
CVE-2011-5263Cross-site scripting (XSS) vulnerability in RetrieveMailExamples in SAP NetWeaver 7.30 and earlier allows remote attacke...
CVE-2011-5262SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL comma...
CVE-2011-5261Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and ...
CVE-2011-5260Cross-site scripting (XSS) vulnerability in SAP/BW/DOC/METADATA in SAP NetWeaver allows remote attackers to inject arbit...
CVE-2011-5259SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attacker...
CVE-2011-5258Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.6.11.2 allow remote attackers to inject arbitr...
CVE-2011-5257Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote att...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now