2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

CVE IDSeverityCVSSDescription
CVE-2011-2482HIGH7.5A certain Red Hat patch to the sctp_sock_migrate function in net/sctp/socket.c in the Linux kernel before 2.6.21, as use...
CVE-2011-1585The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the as...
CVE-2011-1180CRITICAL9.8Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux ...
CVE-2011-4604The bat_socket_read function in net/batman-adv/icmp_socket.c in the Linux kernel before 3.3 allows remote attackers to c...
CVE-2011-4520Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a ...
CVE-2011-4519Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a...
CVE-2011-4518Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remo...
CVE-2011-4609The svc_run function in the RPC implementation in glibc before 2.15 allows remote attackers to cause a denial of service...
CVE-2011-4515Siemens WinCC (TIA Portal) 11 uses a reversible algorithm for storing HMI web-application passwords in world-readable an...
CVE-2011-4966modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not prop...
CVE-2011-1165Vino, possibly before 3.2, does not properly document that it opens ports in UPnP routers when the "Configure network to...
CVE-2011-1164Vino before 2.99.4 can connect external networks contrary to the statement in the vino-preferences dialog box, which mig...
CVE-2011-4969Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows rem...
CVE-2011-2504Untrusted search path vulnerability in x11perfcomp in XFree86 x11perf before 1.5.4 allows local users to gain privileges...
CVE-2011-3201GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter ...
CVE-2011-4318Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does ...
CVE-2011-4355GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the cu...
CVE-2011-3638fs/ext4/extents.c in the Linux kernel before 3.0 does not mark a modified extent as dirty in certain cases of extent spl...
CVE-2011-2905Untrusted search path vulnerability in the perf_config function in tools/perf/util/config.c in perf, as distributed in t...
CVE-2011-2491The Network Lock Manager (NLM) protocol implementation in the NFS client functionality in the Linux kernel before 3.0 al...
CVE-2011-2479MEDIUM5.5The Linux kernel before 2.6.39 does not properly create transparent huge pages in response to a MAP_PRIVATE mmap system ...
CVE-2011-1182kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a s...
CVE-2011-1019The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_S...
CVE-2011-5265Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress ...
CVE-2011-5264Cross-site scripting (XSS) vulnerability in lazyest-backup.php in the Lazyest Backup plugin before 0.2.2 for WordPress a...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now