2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2011-2908Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform bef...
CVE-2011-1096The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platfo...
CVE-2011-4612icecast before 2.3.3 allows remote attackers to inject control characters such as newlines into the error loc (error.log...
CVE-2011-5244Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as ...
CVE-2011-2486nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prev...
CVE-2011-0433Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and p...
CVE-2011-1374Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of s...
CVE-2011-5243TwitterOAuth does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subject...
CVE-2011-5242tmhOAuth before 0.61 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or...
CVE-2011-5241Services_Twitter 0.6.3 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) ...
CVE-2011-5240Magento 1.5 and 1.6.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) o...
CVE-2011-5239CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN)...
CVE-2011-5238google-checkout-php-sample-code before 1.3.2 does not verify that the server hostname matches a domain name in the subje...
CVE-2011-5237PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or s...
CVE-2011-5236Moneris eSelectPlus 2.03 PHP API does not verify that the server hostname matches a domain name in the subject's Common ...
CVE-2011-5235SQL injection vulnerability in mnoGoSearch before 3.3.12 allows remote attackers to execute arbitrary SQL commands via t...
CVE-2011-5234SQL injection vulnerability in user.php in Social Network Community 2 allows remote attackers to execute arbitrary SQL c...
CVE-2011-5233Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows ...
CVE-2011-5232Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0025. Reason: This candidate is a duplicate of...
CVE-2011-5231Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0023. Reason: This candidate is a duplicate of...
CVE-2011-5230Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/Log...
CVE-2011-5229SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attac...
CVE-2011-5228Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote att...
CVE-2011-5227Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1...
CVE-2011-5226Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress all...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now