2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

CVE IDSeverityCVSSDescription
CVE-2011-3202MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the g parameter to index.php in Jcow CMS 4.2 and earlier.
CVE-2011-3183MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.
CVE-2011-2934HIGH8.8A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlie...
CVE-2011-2933HIGH7.2An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failu...
CVE-2011-2706MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
CVE-2011-3203CRITICAL9.8A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2.
CVE-2011-2670MEDIUM6.1Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
CVE-2011-5020CRITICAL9.8An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.
CVE-2011-4595MEDIUM6.1Pretty-Link WordPress plugin 1.5.2 has XSS
CVE-2011-5266CRITICAL9.8Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.
CVE-2011-5250MEDIUM6.5Snare for Linux before 1.7.0 has CSRF in the web interface.
CVE-2011-5247HIGH7.5Snare for Linux before 1.7.0 has password disclosure because the rendered page contains the field RemotePassword.
CVE-2011-5018MEDIUM6.1Koala Framework before 2011-11-21 has XSS via the request_uri parameter.
CVE-2011-3585MEDIUM4.7Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a de...
CVE-2011-1474MEDIUM5.5A locally locally exploitable DOS vulnerability was found in pax-linux versions 2.6.32.33-test79.patch, 2.6.38-test3.pat...
CVE-2011-2717CRITICAL9.8The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitr...
CVE-2011-2523CRITICAL9.8vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
CVE-2011-2515MEDIUM5.3PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation o...
CVE-2011-2480HIGH7.5Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain no...
CVE-2011-2207MEDIUM5.3dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service...
CVE-2011-2187HIGH7.8xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS ...
CVE-2011-2177HIGH7.8OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite ...
CVE-2011-4310HIGH7.5The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.
CVE-2011-1939CRITICAL9.8SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compati...
CVE-2011-1934MEDIUM4.3lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1.

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now