2011 CVE Vulnerabilities
4,899 CVEs published in 2011.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-4591 | — | — | 1.8% | Jul 20, 2012 | Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 an... |
| CVE-2011-4590 | — | — | 1.2% | Jul 20, 2012 | The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maint... |
| CVE-2011-4589 | — | — | 1.3% | Jul 20, 2012 | backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/co... |
| CVE-2011-4588 | — | — | 2.1% | Jul 20, 2012 | The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows... |
| CVE-2011-4587 | — | — | 2.1% | Jul 20, 2012 | lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle cer... |
| CVE-2011-4586 | — | — | 2.1% | Jul 20, 2012 | CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2... |
| CVE-2011-4585 | — | — | 2.1% | Jul 20, 2012 | login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the http... |
| CVE-2011-4584 | — | — | 1.7% | Jul 20, 2012 | The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows r... |
| CVE-2011-4583 | — | — | 1.3% | Jul 20, 2012 | Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (... |
| CVE-2011-4582 | — | — | 1.2% | Jul 20, 2012 | Open redirect vulnerability in the Calendar set page in Moodle 2.1.x before 2.1.3 allows remote authenticated users to r... |
| CVE-2011-4581 | — | — | 1.1% | Jul 20, 2012 | mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover t... |
| CVE-2011-4358 | — | — | 1.6% | Jul 17, 2012 | Unspecified vulnerability in Oracle GlassFish Enterprise Server 3.0.1 and 3.1.1 allows remote attackers to affect confid... |
| CVE-2011-3562 | — | — | 1.2% | Jul 17, 2012 | Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.6, and 11.1.2.0 allows re... |
| CVE-2011-4297 | — | — | 1.6% | Jul 16, 2012 | comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, whi... |
| CVE-2011-4296 | — | — | 1.3% | Jul 16, 2012 | lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creat... |
| CVE-2011-4295 | — | — | 1.3% | Jul 16, 2012 | The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.... |
| CVE-2011-4294 | — | — | 1.5% | Jul 16, 2012 | The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensur... |
| CVE-2011-4293 | — | — | 2.4% | Jul 16, 2012 | The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Sty... |
| CVE-2011-4292 | — | — | 2.0% | Jul 16, 2012 | Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via ... |
| CVE-2011-4291 | — | — | 1.9% | Jul 16, 2012 | Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via ... |
| CVE-2011-4290 | — | — | 1.2% | Jul 16, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attacke... |
| CVE-2011-4289 | — | — | 1.7% | Jul 16, 2012 | Moodle 2.0.x before 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to cours... |
| CVE-2011-4288 | — | — | 1.7% | Jul 16, 2012 | Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, ... |
| CVE-2011-4287 | — | — | 2.1% | Jul 16, 2012 | admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which m... |
| CVE-2011-4286 | — | — | 1.8% | Jul 16, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in the media-filter implementation in filter/mediaplugin/filter.php ... |
Check if your code is affected by 2011 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now