2011 CVE Vulnerabilities
4,899 CVEs published in 2011.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-4573 | — | — | 0.8% | Apr 1, 2014 | Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote a... |
| CVE-2011-3346 | — | — | 0.5% | Apr 1, 2014 | Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest u... |
| CVE-2011-5276 | — | — | 1.1% | Mar 21, 2014 | SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain T... |
| CVE-2011-5275 | — | — | 1.3% | Mar 21, 2014 | The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc use... |
| CVE-2011-5274 | — | — | 2.0% | Mar 21, 2014 | The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before... |
| CVE-2011-5273 | — | — | 1.5% | Mar 21, 2014 | Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows r... |
| CVE-2011-5272 | — | — | 1.1% | Mar 21, 2014 | SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execu... |
| CVE-2011-3199 | — | — | 1.0% | Mar 21, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Domain Technologie Control (DTC) before 0.34.1 allow remote authe... |
| CVE-2011-3198 | — | — | 0.3% | Mar 21, 2014 | Domain Technologie Control (DTC) before 0.34.1 includes a password in the -b command line argument to htpasswd, which mi... |
| CVE-2011-3197 | — | — | 1.2% | Mar 21, 2014 | SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execu... |
| CVE-2011-3196 | — | — | 0.3% | Mar 21, 2014 | The setup script in Domain Technologie Control (DTC) before 0.34.1 uses world-readable permissions for /etc/apache2/apac... |
| CVE-2011-3195 | — | — | 1.5% | Mar 21, 2014 | shared/inc/sql/lists.php in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute ... |
| CVE-2011-3153 | — | — | 0.3% | Mar 6, 2014 | dmrc.c in Light Display Manager (aka LightDM) before 1.1.1 allows local users to read arbitrary files via a symlink atta... |
| CVE-2011-4696 | — | — | 0.8% | Mar 3, 2014 | Directory traversal vulnerability in Eye-Fi Helper before 3.4.23 allows man-in-the-middle attackers to create arbitrary ... |
| CVE-2011-3634 | — | — | 0.8% | Mar 1, 2014 | methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Hos... |
| CVE-2011-4580 | — | — | 1.0% | Feb 26, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remot... |
| CVE-2011-4111 | — | — | 2.3% | Feb 26, 2014 | Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x... |
| CVE-2011-2941 | — | — | 1.1% | Feb 26, 2014 | Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect... |
| CVE-2011-1749 | — | — | 0.4% | Feb 26, 2014 | The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to appen... |
| CVE-2011-4083 | — | — | 1.0% | Feb 17, 2014 | The sosreport utility in the Red Hat sos package before 1.7-9 and 2.x before 2.2-17 includes (1) Certificate-based Red H... |
| CVE-2011-3605 | — | — | 1.6% | Feb 17, 2014 | The process_rs function in the router advertisement daemon (radvd) before 1.8.2, when UnicastOnly is enabled, allows rem... |
| CVE-2011-3604 | — | — | 1.6% | Feb 17, 2014 | The process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attackers to cause a denia... |
| CVE-2011-3601 | — | — | 4.0% | Feb 17, 2014 | Buffer overflow in the process_ra function in the router advertisement daemon (radvd) before 1.8.2 allows remote attacke... |
| CVE-2011-0528 | — | — | 1.7% | Feb 17, 2014 | Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet... |
| CVE-2011-3590 | — | — | 0.6% | Feb 15, 2014 | The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.... |
Check if your code is affected by 2011 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now