2011 CVE Vulnerabilities

4,899 CVEs published in 2011.

CVE IDSeverityCVSSDescription
CVE-2011-0529HIGH7.5Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.
CVE-2011-1028CRITICAL9.8The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smar...
CVE-2011-3352MEDIUM4.8Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by se...
CVE-2011-3350CRITICAL9.8masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privi...
CVE-2011-3349HIGH7.8lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled ...
CVE-2011-2924MEDIUM5.5foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by renderin...
CVE-2011-2923MEDIUM5.5foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering t...
CVE-2011-2922HIGH7.8ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privi...
CVE-2011-2921CRITICAL9.8ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified com...
CVE-2011-4968MEDIUM4.8nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle at...
CVE-2011-4967HIGH7.5tog-Pegasus has a package hash collision DoS vulnerability
CVE-2011-4954HIGH7.8cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE
CVE-2011-4952HIGH8.8cobbler: Web interface lacks CSRF protection when using Django framework
CVE-2011-4919HIGH7.5mpack 1.6 has information disclosure via eavesdropping on mails sent by other users
CVE-2011-5331CRITICAL9.8Distributed Ruby (aka DRuby) 1.8 mishandles instance_eval.
CVE-2011-5330CRITICAL9.8Distributed Ruby (aka DRuby) 1.8 mishandles the sending of syscalls.
CVE-2011-2916MEDIUM5.5qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-exec...
CVE-2011-2910MEDIUM6.7The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call...
CVE-2011-2726HIGH7.5An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File uploa...
CVE-2011-0703CRITICAL9.8In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to over...
CVE-2011-1930CRITICAL9.8In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This...
CVE-2011-1588HIGH7.8Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
CVE-2011-1490MEDIUM5.5A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulese...
CVE-2011-1489MEDIUM5.5A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rules...
CVE-2011-1488MEDIUM5.5A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgRed...

Check if your code is affected by 2011 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now