2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

CVE IDSeverityCVSSDescription
CVE-2011-4908CRITICAL9.8TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
CVE-2011-4906CRITICAL9.8Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
CVE-2011-3901HIGH7.5Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.
CVE-2011-3336HIGH7.5regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.
CVE-2011-2499MEDIUM6.1Mambo CMS through 4.6.5 has multiple XSS.
CVE-2011-2343LOW2.4The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an ...
CVE-2011-4338HIGH7.8Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in sham...
CVE-2011-4661HIGH7.5A memory leak vulnerability exists in Cisco IOS before 15.2(1)T due to a memory leak in the HTTP PROXY Server process (a...
CVE-2011-4938MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Ariadne 2.7.6 allow remote attackers to inject arbitrary web scri...
CVE-2011-1596Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2011-3642CRITICAL9.6Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) ext...
CVE-2011-1086MEDIUM6.1Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitra...
CVE-2011-1085HIGH8.8CSRF vulnerability in Smoothwall Express 3.
CVE-2011-1084MEDIUM6.1A cross-site scripting (XSS) vulnerability in Smoothwall Express 3.
CVE-2011-1597HIGH8.8OpenVAS Manager v2.0.3 allows plugin remote code execution.
CVE-2011-1517CRITICAL9.8SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. ...
CVE-2011-1151CRITICAL9.1Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.
CVE-2011-1150MEDIUM6.1bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.
CVE-2011-1069MEDIUM6.1PHPShop through 0.8.1 has XSS.
CVE-2011-1009MEDIUM6.1Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.
CVE-2011-0525HIGH8.8Batavi before 1.0 has CSRF.
CVE-2011-0220MEDIUM5.5Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.
CVE-2011-4912MEDIUM5.3Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
CVE-2011-4937HIGH7.5Joomla! 1.7.1 has core information disclosure due to inadequate error checking.
CVE-2011-3629HIGH7.5Joomla! core 1.7.1 allows information disclosure due to weak encryption

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now