2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

CVE IDSeverityCVSSDescription
CVE-2011-4573Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote a...
CVE-2011-3346Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest u...
CVE-2011-5276SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain T...
CVE-2011-5275The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc use...
CVE-2011-5274The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before...
CVE-2011-5273Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows r...
CVE-2011-5272SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execu...
CVE-2011-3199Multiple cross-site scripting (XSS) vulnerabilities in Domain Technologie Control (DTC) before 0.34.1 allow remote authe...
CVE-2011-3198Domain Technologie Control (DTC) before 0.34.1 includes a password in the -b command line argument to htpasswd, which mi...
CVE-2011-3197SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execu...
CVE-2011-3196The setup script in Domain Technologie Control (DTC) before 0.34.1 uses world-readable permissions for /etc/apache2/apac...
CVE-2011-3195shared/inc/sql/lists.php in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute ...
CVE-2011-3153dmrc.c in Light Display Manager (aka LightDM) before 1.1.1 allows local users to read arbitrary files via a symlink atta...
CVE-2011-4696Directory traversal vulnerability in Eye-Fi Helper before 3.4.23 allows man-in-the-middle attackers to create arbitrary ...
CVE-2011-3634methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Hos...
CVE-2011-4580Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remot...
CVE-2011-4111Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x...
CVE-2011-2941Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect...
CVE-2011-1749The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to appen...
CVE-2011-4083The sosreport utility in the Red Hat sos package before 1.7-9 and 2.x before 2.2-17 includes (1) Certificate-based Red H...
CVE-2011-3605The process_rs function in the router advertisement daemon (radvd) before 1.8.2, when UnicastOnly is enabled, allows rem...
CVE-2011-3604The process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attackers to cause a denia...
CVE-2011-3601Buffer overflow in the process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attacke...
CVE-2011-0528Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet...
CVE-2011-3590The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2....

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now