2011 CVE Vulnerabilities
4,899 CVEs published in 2011.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-4327 | MEDIUM | 5.5 | 0.4% | Feb 3, 2014 | ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open ... |
| CVE-2011-5270 | — | — | 1.8% | Jan 21, 2014 | wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allow... |
| CVE-2011-1936 | — | — | 0.5% | Jan 7, 2014 | Xen, when using x86 Intel processors and the VMX virtualization extension is enabled, does not properly handle cpuid ins... |
| CVE-2011-1780 | — | — | 0.7% | Jan 7, 2014 | The instruction emulation in Xen 3.0.3 allows local SMP guest users to cause a denial of service (host crash) by replaci... |
| CVE-2011-1763 | — | — | 0.6% | Jan 7, 2014 | The get_free_port function in Xen allows local authenticated DomU users to cause a denial of service or possibly gain pr... |
| CVE-2011-1166 | — | — | 0.7% | Jan 7, 2014 | Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user m... |
| CVE-2011-5269 | — | — | 1.1% | Jan 2, 2014 | Cross-site scripting (XSS) vulnerability in ProjectForge before 3.5.3 allows remote authenticated users to inject arbitr... |
| CVE-2011-2519 | — | — | 0.7% | Dec 27, 2013 | Xen in the Linux kernel, when running a guest on a host without hardware assisted paging (HAP), allows guest users to ca... |
| CVE-2011-5268 | — | — | 1.5% | Dec 24, 2013 | connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of ser... |
| CVE-2011-4971 | — | — | 22.3% | Dec 12, 2013 | Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin... |
| CVE-2011-4351 | — | — | 3.3% | Dec 9, 2013 | Buffer overflow in FFmpeg before 0.5.6, 0.6.x before 0.6.4, 0.7.x before 0.7.8, and 0.8.x before 0.8.8 allows remote att... |
| CVE-2011-3950 | — | — | 2.0% | Dec 9, 2013 | The dirac_decode_data_unit function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an un... |
| CVE-2011-3949 | — | — | 2.0% | Dec 9, 2013 | The dirac_unpack_idwt_params function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an ... |
| CVE-2011-3946 | — | — | 5.7% | Dec 9, 2013 | The ff_h264_decode_sei function in libavcodec/h264_sei.c in FFmpeg before 0.10 allows remote attackers to have an unspec... |
| CVE-2011-3944 | — | — | 2.4% | Dec 9, 2013 | The smacker_decode_header_tree function in libavcodec/smacker.c in FFmpeg before 0.10 allows remote attackers to have an... |
| CVE-2011-3941 | — | — | 2.3% | Dec 9, 2013 | The decode_mb function in libavcodec/error_resilience.c in FFmpeg before 0.10 allows remote attackers to have an unspeci... |
| CVE-2011-3935 | — | — | 2.0% | Dec 9, 2013 | The codec_get_buffer function in ffmpeg.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact vi... |
| CVE-2011-3934 | — | — | 2.0% | Dec 9, 2013 | Double free vulnerability in the vp3_update_thread_context function in libavcodec/vp3.c in FFmpeg before 0.10 allows rem... |
| CVE-2011-5267 | — | — | 1.9% | Nov 5, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as... |
| CVE-2011-4106 | — | — | 23.2% | Oct 26, 2013 | TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote a... |
| CVE-2011-2901 | — | — | 0.6% | Oct 1, 2013 | Off-by-one error in the __addr_ok macro in Xen 3.3 and earlier allows local 64 bit PV guest administrators to cause a de... |
| CVE-2011-4402 | — | — | — | Oct 1, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ... |
| CVE-2011-4401 | — | — | — | Oct 1, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ... |
| CVE-2011-4400 | — | — | — | Oct 1, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ... |
| CVE-2011-4399 | — | — | — | Oct 1, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ... |
Check if your code is affected by 2011 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now