2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2011-4931HIGH7.5gpw generates shorter passwords than required
CVE-2011-2538HIGH7.2Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, au...
CVE-2011-3147HIGH8.6Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciou...
CVE-2011-4182HIGH7.3Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to c...
CVE-2011-4181HIGH7.5A vulnerability in open build service allows remote attackers to gain access to source files even though source access i...
CVE-2011-0467HIGH8.8A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows auth...
CVE-2011-3178HIGH8.1In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used...
CVE-2011-5325HIGH7.5Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point...
CVE-2011-4087HIGH7.5The br_parse_ip_options function in net/bridge/br_netfilter.c in the Linux kernel before 2.6.39 does not properly initia...
CVE-2011-2482HIGH7.5A certain Red Hat patch to the sctp_sock_migrate function in net/sctp/socket.c in the Linux kernel before 2.6.21, as use...
CVE-2011-3359HIGH7.5The dma_rx function in drivers/net/wireless/b43/dma.c in the Linux kernel before 2.6.39 does not properly allocate recei...
CVE-2011-3191HIGH8.8Integer signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel before 3.1 allows remote ...
CVE-2011-2699HIGH7.5The IPv6 implementation in the Linux kernel before 3.1 does not generate Fragment Identification values separately for e...
CVE-2011-3045HIGH8.8Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chro...
CVE-2011-2525HIGH7.8The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc functi...
CVE-2011-3406HIGH8.8Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Director...
CVE-2011-2016HIGH7.3Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Se...
CVE-2011-3402HIGH8.8Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Wind...
CVE-2011-2058HIGH7.5The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pa...
CVE-2011-2057HIGH7.5The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle (1) a loop between a dot1x en...
CVE-2011-1640HIGH7.5The ethernet-lldp component in Cisco IOS 12.2 before 12.2(33)SXJ1 does not properly support a large number of LLDP Manag...
CVE-2011-2005HIGH7.8afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly valid...
CVE-2011-1985HIGH7.1win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W...
CVE-2011-2189HIGH7.5net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cle...
CVE-2011-3288HIGH7.5Cisco Unified Presence before 8.5(4) does not properly detect recursion during entity expansion, which allows remote att...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now