Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-4620

Published Dec 31, 2011

Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote attackers to execute arbitrary…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4617

Published Dec 31, 2011

virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary files via a symlink attack on a certain file in /tmp/.

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1710

Published Dec 31, 2011

Multiple integer overflows in the HTTP server in the Novell XTier framework 3.1.8 allow remote attackers to cause a denial of service (service crash) or possibly execute arbitrary…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5045

Published Dec 30, 2011

Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inject arbitrary web script or HTML via the page_info_message p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5044

Published Dec 30, 2011

SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute arbitrary code by replacing Diagnose.exe with a Trojan hors…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5043

Published Dec 30, 2011

TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a buffer overflow.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5042

Published Dec 30, 2011

Cross-site scripting (XSS) vulnerability in inc/lib/lib.base.php in SASHA 0.2.0 allows remote attackers to inject arbitrary web script or HTML via the instructors parameter. NOTE…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5041

Published Dec 30, 2011

Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) d parameter in a blocks action…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5040

Published Dec 30, 2011

Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitrary web script or HTML via the config parameter to (1) naloz…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5039

Published Dec 30, 2011

Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to log…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5038

Published Dec 30, 2011

SQL injection vulnerability in hitCode hitAppoint 4.5.17 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to index.php. N…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5037

Published Dec 30, 2011

Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of servi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5036

Published Dec 30, 2011

Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, whic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5035

Published Dec 30, 2011

Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values f…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2011-5034

Published Dec 30, 2011

Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4885

Published Dec 30, 2011

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial o…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2011-4838

Published Dec 30, 2011

JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of ser…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4815

Published Dec 30, 2011

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4462

Published Dec 30, 2011

Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a d…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 4,150 CVEsPage 1 of 166