2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2011-2908——Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform bef...
CVE-2011-1096——The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platfo...
CVE-2011-4612——icecast before 2.3.3 allows remote attackers to inject control characters such as newlines into the error loc (error.log...
CVE-2011-5244——Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as ...
CVE-2011-2486——nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prev...
CVE-2011-0433——Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and p...
CVE-2011-1374——Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of s...
CVE-2011-5243——TwitterOAuth does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subject...
CVE-2011-5242——tmhOAuth before 0.61 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or...
CVE-2011-5241——Services_Twitter 0.6.3 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) ...
CVE-2011-5240——Magento 1.5 and 1.6.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) o...
CVE-2011-5239——CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN)...
CVE-2011-5238——google-checkout-php-sample-code before 1.3.2 does not verify that the server hostname matches a domain name in the subje...
CVE-2011-5237——PayPal WPS ToolKit does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or s...
CVE-2011-5236——Moneris eSelectPlus 2.03 PHP API does not verify that the server hostname matches a domain name in the subject's Common ...
CVE-2011-5235——SQL injection vulnerability in mnoGoSearch before 3.3.12 allows remote attackers to execute arbitrary SQL commands via t...
CVE-2011-5234——SQL injection vulnerability in user.php in Social Network Community 2 allows remote attackers to execute arbitrary SQL c...
CVE-2011-5233——Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows ...
CVE-2011-5232——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0025. Reason: This candidate is a duplicate of...
CVE-2011-5231——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0023. Reason: This candidate is a duplicate of...
CVE-2011-5230——Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/Log...
CVE-2011-5229——SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attac...
CVE-2011-5228——Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote att...
CVE-2011-5227——Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1...
CVE-2011-5226——Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress all...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now