2011 CVE Vulnerabilities
4,899 CVEs published in 2011.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-3437 | — | — | 3.0% | Oct 14, 2011 | Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to ex... |
| CVE-2011-3436 | — | — | 1.7% | Oct 14, 2011 | Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before chang... |
| CVE-2011-3435 | — | — | 0.8% | Oct 14, 2011 | Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via ... |
| CVE-2011-3434 | — | — | 1.7% | Oct 14, 2011 | The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remot... |
| CVE-2011-3432 | — | — | 2.2% | Oct 14, 2011 | The UIKit Alerts component in Apple iOS before 5 allows remote attackers to cause a denial of service (device hang) via ... |
| CVE-2011-3431 | — | — | 0.4% | Oct 14, 2011 | The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which... |
| CVE-2011-3430 | — | — | 1.8% | Oct 14, 2011 | The Settings component in Apple iOS before 5, when a configuration profile is used for a locale other than English, does... |
| CVE-2011-3429 | — | — | 0.4% | Oct 14, 2011 | The Settings component in Apple iOS before 5 stores a cleartext parental-restrictions passcode in an unspecified file, w... |
| CVE-2011-3427 | — | — | 0.9% | Oct 14, 2011 | The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash... |
| CVE-2011-3426 | — | — | 1.8% | Oct 14, 2011 | Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary w... |
| CVE-2011-3261 | — | — | 2.9% | Oct 14, 2011 | Double free vulnerability in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cau... |
| CVE-2011-3260 | — | — | 3.4% | Oct 14, 2011 | Buffer overflow in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denia... |
| CVE-2011-3259 | — | — | 2.4% | Oct 14, 2011 | The kernel in Apple iOS before 5 and Apple TV before 4.4 does not properly recover memory allocated for incomplete TCP c... |
| CVE-2011-3257 | — | — | 0.4% | Oct 14, 2011 | The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the ... |
| CVE-2011-3256 | — | — | 4.1% | Oct 14, 2011 | FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other... |
| CVE-2011-3255 | — | — | 1.7% | Oct 14, 2011 | CFNetwork in Apple iOS before 5 stores AppleID credentials in an unspecified file, which makes it easier for remote atta... |
| CVE-2011-3254 | — | — | 1.3% | Oct 14, 2011 | Cross-site scripting (XSS) vulnerability in Calendar in Apple iOS before 5 allows remote attackers to inject arbitrary w... |
| CVE-2011-3253 | — | — | 0.6% | Oct 14, 2011 | CalDAV in Apple iOS before 5 does not validate X.509 certificates for SSL sessions, which allows man-in-the-middle attac... |
| CVE-2011-3246 | — | — | 3.0% | Oct 14, 2011 | CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote at... |
| CVE-2011-3245 | — | — | 0.4% | Oct 14, 2011 | The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent us... |
| CVE-2011-3243 | — | — | 2.0% | Oct 14, 2011 | Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote... |
| CVE-2011-3242 | — | — | 1.4% | Oct 14, 2011 | The Private Browsing feature in Apple Safari before 5.1.1 on Mac OS X does not properly recognize the Always value of th... |
| CVE-2011-3231 | — | — | 1.4% | Oct 14, 2011 | The SSL implementation in Apple Safari before 5.1.1 on Mac OS X before 10.7 accesses uninitialized memory during the pro... |
| CVE-2011-3230 | — | — | 50.2% | Oct 14, 2011 | Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers ... |
| CVE-2011-3229 | — | — | 2.1% | Oct 14, 2011 | Directory traversal vulnerability in Apple Safari before 5.1.1 allows remote attackers to execute arbitrary JavaScript c... |
Check if your code is affected by 2011 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now