2011 CVE Vulnerabilities

4,898 CVEs published in 2011.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2011-4076MEDIUM5.9OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC...
CVE-2011-3624MEDIUM5.3Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwa...
CVE-2011-3617MEDIUM6.5Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.
CVE-2011-3609MEDIUM6.5A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the managem...
CVE-2011-3606MEDIUM5.4A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration con...
CVE-2011-3373MEDIUM6.1Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when th...
CVE-2011-4924MEDIUM6.1Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x...
CVE-2011-4455MEDIUM6.1Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web scr...
CVE-2011-4454MEDIUM6.1Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web...
CVE-2011-3352MEDIUM4.8Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by se...
CVE-2011-2924MEDIUM5.5foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by renderin...
CVE-2011-2923MEDIUM5.5foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering t...
CVE-2011-4968MEDIUM4.8nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle at...
CVE-2011-2916MEDIUM5.5qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-exec...
CVE-2011-2910MEDIUM6.7The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call...
CVE-2011-1490MEDIUM5.5A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulese...
CVE-2011-1489MEDIUM5.5A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rules...
CVE-2011-1488MEDIUM5.5A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgRed...
CVE-2011-1136MEDIUM4.7In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to th...
CVE-2011-0544MEDIUM6.1phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.
CVE-2011-1803MEDIUM6.5An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Bl...
CVE-2011-1802MEDIUM6.5WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allows remote attackers t...
CVE-2011-2334MEDIUM6.5Use after free vulnerability exists in WebKit in Google Chrome before Blink M12 in RenderLayerwhen removing elements wit...
CVE-2011-5271MEDIUM5.5Pacemaker before 1.1.6 configure script creates temporary files insecurely
CVE-2011-3370MEDIUM6.1statusnet before 0.9.9 has XSS

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now