2011 CVE Vulnerabilities
4,899 CVEs published in 2011.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-1933 | CRITICAL | 9.8 | 1.6% | Nov 26, 2019 | SQL injection vulnerability in Jifty::DBI before 0.68. |
| CVE-2011-4350 | MEDIUM | 6.5 | 16.1% | Nov 26, 2019 | Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user cou... |
| CVE-2011-4121 | CRITICAL | 9.8 | 2.5% | Nov 26, 2019 | The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value ... |
| CVE-2011-4120 | CRITICAL | 9.8 | 2.0% | Nov 26, 2019 | Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used ... |
| CVE-2011-4090 | MEDIUM | 6.1 | 3.1% | Nov 26, 2019 | Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation. |
| CVE-2011-4082 | HIGH | 7.5 | 1.7% | Nov 26, 2019 | A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-L... |
| CVE-2011-4076 | MEDIUM | 5.9 | 1.4% | Nov 26, 2019 | OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC... |
| CVE-2011-3632 | HIGH | 7.1 | 0.5% | Nov 26, 2019 | Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw ... |
| CVE-2011-3631 | HIGH | 8.8 | 2.7% | Nov 26, 2019 | Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string le... |
| CVE-2011-3630 | HIGH | 8.8 | 2.7% | Nov 26, 2019 | Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with dee... |
| CVE-2011-3624 | MEDIUM | 5.3 | 1.5% | Nov 26, 2019 | Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwa... |
| CVE-2011-3617 | MEDIUM | 6.5 | 0.9% | Nov 26, 2019 | Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases. |
| CVE-2011-3609 | MEDIUM | 6.5 | 1.3% | Nov 26, 2019 | A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the managem... |
| CVE-2011-3606 | MEDIUM | 5.4 | 1.1% | Nov 26, 2019 | A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration con... |
| CVE-2011-3600 | HIGH | 7.5 | 15.9% | Nov 26, 2019 | The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing ... |
| CVE-2011-3596 | HIGH | 7.5 | 11.1% | Nov 26, 2019 | Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request. |
| CVE-2011-3584 | CRITICAL | 9.8 | 1.2% | Nov 26, 2019 | The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-s... |
| CVE-2011-3583 | CRITICAL | 9.8 | 1.4% | Nov 26, 2019 | It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not prope... |
| CVE-2011-3374 | LOW | 3.7 | 1.2% | Nov 26, 2019 | It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a... |
| CVE-2011-3373 | MEDIUM | 6.1 | 1.3% | Nov 25, 2019 | Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when th... |
| CVE-2011-3355 | HIGH | 7.3 | 0.8% | Nov 25, 2019 | evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messag... |
| CVE-2011-3351 | HIGH | 7.1 | 0.4% | Nov 25, 2019 | openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics docume... |
| CVE-2011-4924 | MEDIUM | 6.1 | 1.4% | Nov 25, 2019 | Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x... |
| CVE-2011-4455 | MEDIUM | 6.1 | 0.9% | Nov 20, 2019 | Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web scr... |
| CVE-2011-4454 | MEDIUM | 6.1 | 0.9% | Nov 20, 2019 | Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web... |
Check if your code is affected by 2011 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now