2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

CVE IDSeverityCVSSDescription
CVE-2011-4327MEDIUM5.5ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open ...
CVE-2011-5270wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allow...
CVE-2011-1936Xen, when using x86 Intel processors and the VMX virtualization extension is enabled, does not properly handle cpuid ins...
CVE-2011-1780The instruction emulation in Xen 3.0.3 allows local SMP guest users to cause a denial of service (host crash) by replaci...
CVE-2011-1763The get_free_port function in Xen allows local authenticated DomU users to cause a denial of service or possibly gain pr...
CVE-2011-1166Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user m...
CVE-2011-5269Cross-site scripting (XSS) vulnerability in ProjectForge before 3.5.3 allows remote authenticated users to inject arbitr...
CVE-2011-2519Xen in the Linux kernel, when running a guest on a host without hardware assisted paging (HAP), allows guest users to ca...
CVE-2011-5268connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of ser...
CVE-2011-4971Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin...
CVE-2011-4351Buffer overflow in FFmpeg before 0.5.6, 0.6.x before 0.6.4, 0.7.x before 0.7.8, and 0.8.x before 0.8.8 allows remote att...
CVE-2011-3950The dirac_decode_data_unit function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an un...
CVE-2011-3949The dirac_unpack_idwt_params function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an ...
CVE-2011-3946The ff_h264_decode_sei function in libavcodec/h264_sei.c in FFmpeg before 0.10 allows remote attackers to have an unspec...
CVE-2011-3944The smacker_decode_header_tree function in libavcodec/smacker.c in FFmpeg before 0.10 allows remote attackers to have an...
CVE-2011-3941The decode_mb function in libavcodec/error_resilience.c in FFmpeg before 0.10 allows remote attackers to have an unspeci...
CVE-2011-3935The codec_get_buffer function in ffmpeg.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact vi...
CVE-2011-3934Double free vulnerability in the vp3_update_thread_context function in libavcodec/vp3.c in FFmpeg before 0.10 allows rem...
CVE-2011-5267Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as...
CVE-2011-4106TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote a...
CVE-2011-2901Off-by-one error in the __addr_ok macro in Xen 3.3 and earlier allows local 64 bit PV guest administrators to cause a de...
CVE-2011-4402Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ...
CVE-2011-4401Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ...
CVE-2011-4400Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ...
CVE-2011-4399Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now