2011 CVE Vulnerabilities

4,898 CVEs published in 2011.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2011-0220MEDIUM5.5Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.
CVE-2011-4912MEDIUM5.3Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
CVE-2011-3622MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the admin login screen in Phorum before 5.2.18.
CVE-2011-3610MEDIUM6.1A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud paramete...
CVE-2011-3595MEDIUM5.4Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, exte...
CVE-2011-5282MEDIUM5.3mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled.
CVE-2011-4095MEDIUM6.1Jara 1.6 has an XSS vulnerability
CVE-2011-2669MEDIUM6.5Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.
CVE-2011-4907MEDIUM5.3Joomla! 1.5x through 1.5.12: Missing JEXEC Check
CVE-2011-4336MEDIUM6.1Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
CVE-2011-2714MEDIUM6.1A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of...
CVE-2011-3202MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the g parameter to index.php in Jcow CMS 4.2 and earlier.
CVE-2011-3183MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.
CVE-2011-2706MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
CVE-2011-2670MEDIUM6.1Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
CVE-2011-4595MEDIUM6.1Pretty-Link WordPress plugin 1.5.2 has XSS
CVE-2011-5250MEDIUM6.5Snare for Linux before 1.7.0 has CSRF in the web interface.
CVE-2011-5018MEDIUM6.1Koala Framework before 2011-11-21 has XSS via the request_uri parameter.
CVE-2011-3585MEDIUM4.7Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a de...
CVE-2011-1474MEDIUM5.5A locally locally exploitable DOS vulnerability was found in pax-linux versions 2.6.32.33-test79.patch, 2.6.38-test3.pat...
CVE-2011-2515MEDIUM5.3PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation o...
CVE-2011-2207MEDIUM5.3dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service...
CVE-2011-1934MEDIUM4.3lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1.
CVE-2011-4350MEDIUM6.5Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user cou...
CVE-2011-4090MEDIUM6.1Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now