2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

CVE IDSeverityCVSSDescription
CVE-2011-1933CRITICAL9.8SQL injection vulnerability in Jifty::DBI before 0.68.
CVE-2011-4350MEDIUM6.5Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user cou...
CVE-2011-4121CRITICAL9.8The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value ...
CVE-2011-4120CRITICAL9.8Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used ...
CVE-2011-4090MEDIUM6.1Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
CVE-2011-4082HIGH7.5A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-L...
CVE-2011-4076MEDIUM5.9OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC...
CVE-2011-3632HIGH7.1Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw ...
CVE-2011-3631HIGH8.8Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string le...
CVE-2011-3630HIGH8.8Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with dee...
CVE-2011-3624MEDIUM5.3Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwa...
CVE-2011-3617MEDIUM6.5Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.
CVE-2011-3609MEDIUM6.5A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the managem...
CVE-2011-3606MEDIUM5.4A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration con...
CVE-2011-3600HIGH7.5The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing ...
CVE-2011-3596HIGH7.5Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.
CVE-2011-3584CRITICAL9.8The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-s...
CVE-2011-3583CRITICAL9.8It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not prope...
CVE-2011-3374LOW3.7It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a...
CVE-2011-3373MEDIUM6.1Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when th...
CVE-2011-3355HIGH7.3evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messag...
CVE-2011-3351HIGH7.1openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics docume...
CVE-2011-4924MEDIUM6.1Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x...
CVE-2011-4455MEDIUM6.1Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web scr...
CVE-2011-4454MEDIUM6.1Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now