2011 CVE Vulnerabilities
4,899 CVEs published in 2011.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-3985 | — | — | 0.8% | Nov 9, 2011 | Cross-site scripting (XSS) vulnerability in Plume before 1.2.3 allows remote attackers to inject arbitrary web script or... |
| CVE-2011-2740 | — | — | 3.4% | Nov 9, 2011 | EMC RSA Key Manager (RKM) Appliance 2.7 SP1 before 2.7.1.6, when Firefox 4.x or 5.0 is used, does not properly terminate... |
| CVE-2011-2739 | — | — | 2.7% | Nov 9, 2011 | The file-blocking feature in EMC Documentum eRoom 7.3.x and 7.4.x before 7.4.3.g does not properly restrict the uploadin... |
| CVE-2011-1373 | — | — | 0.3% | Nov 9, 2011 | Unspecified vulnerability in IBM DB2 9.7 before FP5 on UNIX, when the Self Tuning Memory Manager (STMM) feature and the ... |
| CVE-2011-3999 | — | — | 0.8% | Nov 9, 2011 | Cross-site scripting (XSS) vulnerability in the RSS/Atom feed-reader implementation in Iwate Portal Bar allows remote at... |
| CVE-2011-3998 | — | — | 0.8% | Nov 9, 2011 | Cross-site scripting (XSS) vulnerability in Apple WebObjects 5.2 and earlier allows remote attackers to inject arbitrary... |
| CVE-2011-3997 | — | — | 1.4% | Nov 9, 2011 | Opengear console servers with firmware before 2.2.1 allow remote attackers to bypass authentication, and modify settings... |
| CVE-2011-3655 | — | — | 1.9% | Nov 9, 2011 | Mozilla Firefox 4.x through 7.0 and Thunderbird 5.0 through 7.0 perform access control without checking for use of the N... |
| CVE-2011-3654 | — | — | 4.4% | Nov 9, 2011 | The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly handle links from SVG mpat... |
| CVE-2011-3653 | — | — | 1.0% | Nov 9, 2011 | Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior ... |
| CVE-2011-3652 | — | — | 3.2% | Nov 9, 2011 | The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly allocate memory, which all... |
| CVE-2011-3651 | — | — | 5.7% | Nov 9, 2011 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 7.0 and Thunderbird 7.0 allow remote attac... |
| CVE-2011-3650 | — | — | 2.3% | Nov 9, 2011 | Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handl... |
| CVE-2011-3649 | — | — | 0.9% | Nov 9, 2011 | Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azur... |
| CVE-2011-3648 | — | — | 1.5% | Nov 9, 2011 | Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1... |
| CVE-2011-3647 | — | — | 1.9% | Nov 9, 2011 | The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWr... |
| CVE-2011-4000 | — | — | 4.2% | Nov 8, 2011 | Buffer overflow in ChaSen 2.4.x allows remote attackers to execute arbitrary code via a crafted string. |
| CVE-2011-2449 | — | — | 3.7% | Nov 8, 2011 | The TextXtra module in Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a de... |
| CVE-2011-2448 | — | — | 3.7% | Nov 8, 2011 | The DIRapi library in Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a den... |
| CVE-2011-2447 | — | — | 3.7% | Nov 8, 2011 | Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a denial of service (memory... |
| CVE-2011-2446 | — | — | 3.7% | Nov 8, 2011 | The DIRapi library in Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a den... |
| CVE-2011-2016 | HIGH | 7.3 | 8.1% | Nov 8, 2011 | Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Se... |
| CVE-2011-2014 | — | — | 11.0% | Nov 8, 2011 | The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active D... |
| CVE-2011-2013 | CRITICAL | 9.8 | 33.7% | Nov 8, 2011 | Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, a... |
| CVE-2011-2004 | — | — | 24.6% | Nov 8, 2011 | Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 ... |
Check if your code is affected by 2011 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now