2011 CVE Vulnerabilities
4,899 CVEs published in 2011.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-4908 | CRITICAL | 9.8 | 55.8% | Feb 12, 2020 | TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php. |
| CVE-2011-4906 | CRITICAL | 9.8 | 9.6% | Feb 12, 2020 | Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution. |
| CVE-2011-3901 | HIGH | 7.5 | 0.7% | Feb 12, 2020 | Android SQLite Journal before 4.0.1 has an information disclosure vulnerability. |
| CVE-2011-3336 | HIGH | 7.5 | 6.5% | Feb 12, 2020 | regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion. |
| CVE-2011-2499 | MEDIUM | 6.1 | 0.6% | Feb 12, 2020 | Mambo CMS through 4.6.5 has multiple XSS. |
| CVE-2011-2343 | LOW | 2.4 | 0.2% | Feb 12, 2020 | The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an ... |
| CVE-2011-4338 | HIGH | 7.8 | 0.4% | Feb 12, 2020 | Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in sham... |
| CVE-2011-4661 | HIGH | 7.5 | 1.0% | Feb 12, 2020 | A memory leak vulnerability exists in Cisco IOS before 15.2(1)T due to a memory leak in the HTTP PROXY Server process (a... |
| CVE-2011-4938 | MEDIUM | 6.1 | 1.2% | Feb 11, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Ariadne 2.7.6 allow remote attackers to inject arbitrary web scri... |
| CVE-2011-1596 | — | — | — | Feb 10, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2011-3642 | CRITICAL | 9.6 | 7.3% | Feb 8, 2020 | Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) ext... |
| CVE-2011-1086 | MEDIUM | 6.1 | 1.7% | Feb 7, 2020 | Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitra... |
| CVE-2011-1085 | HIGH | 8.8 | 0.5% | Feb 7, 2020 | CSRF vulnerability in Smoothwall Express 3. |
| CVE-2011-1084 | MEDIUM | 6.1 | 0.6% | Feb 7, 2020 | A cross-site scripting (XSS) vulnerability in Smoothwall Express 3. |
| CVE-2011-1597 | HIGH | 8.8 | 1.8% | Feb 6, 2020 | OpenVAS Manager v2.0.3 allows plugin remote code execution. |
| CVE-2011-1517 | CRITICAL | 9.8 | 4.2% | Feb 5, 2020 | SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. ... |
| CVE-2011-1151 | CRITICAL | 9.1 | 1.7% | Feb 5, 2020 | Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters. |
| CVE-2011-1150 | MEDIUM | 6.1 | 0.8% | Feb 5, 2020 | bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter. |
| CVE-2011-1069 | MEDIUM | 6.1 | 0.7% | Feb 5, 2020 | PHPShop through 0.8.1 has XSS. |
| CVE-2011-1009 | MEDIUM | 6.1 | 0.8% | Feb 5, 2020 | Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter. |
| CVE-2011-0525 | HIGH | 8.8 | 0.5% | Feb 5, 2020 | Batavi before 1.0 has CSRF. |
| CVE-2011-0220 | MEDIUM | 5.5 | 0.3% | Feb 5, 2020 | Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet. |
| CVE-2011-4912 | MEDIUM | 5.3 | 0.8% | Feb 4, 2020 | Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass. |
| CVE-2011-4937 | HIGH | 7.5 | 1.6% | Feb 4, 2020 | Joomla! 1.7.1 has core information disclosure due to inadequate error checking. |
| CVE-2011-3629 | HIGH | 7.5 | 1.1% | Feb 4, 2020 | Joomla! core 1.7.1 allows information disclosure due to weak encryption |
Check if your code is affected by 2011 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now