Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-0040

Published Feb 9, 2011

The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0920

Published Feb 8, 2011

The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and execut…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0919

Published Feb 8, 2011

Multiple stack-based buffer overflows in the (1) POP3 and (2) IMAP services in IBM Lotus Domino allow remote attackers to execute arbitrary code via non-printable characters in an…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0918

Published Feb 8, 2011

Stack-based buffer overflow in the NRouter (aka Router) service in IBM Lotus Domino allows remote attackers to execute arbitrary code via long filenames associated with Content-ID…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0917

Published Feb 8, 2011

Buffer overflow in nLDAP.exe in IBM Lotus Domino allows remote attackers to execute arbitrary code via a long string in an LDAP Bind operation, aka SPR KLYH87LMVX.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0916

Published Feb 8, 2011

Stack-based buffer overflow in the SMTP service in IBM Lotus Domino allows remote attackers to execute arbitrary code via long arguments in a filename parameter in a malformed MIM…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0915

Published Feb 8, 2011

Stack-based buffer overflow in nrouter.exe in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a long name parameter in a Content-Type header in…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0914

Published Feb 8, 2011

Integer signedness error in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP clie…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0913

Published Feb 8, 2011

Stack-based buffer overflow in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP g…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0912

Published Feb 8, 2011

Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0911

Published Feb 8, 2011

Cross-site scripting (XSS) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE:…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0538

Published Feb 8, 2011

Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format, which allows remote attacker…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2011-0535

Published Feb 8, 2011

Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4729

Published Feb 8, 2011

Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier for remote attackers to generat…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4728

Published Feb 8, 2011

Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protection mechanisms based on randomi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0910

Published Feb 8, 2011

The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain access to arbitrary user account…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0909

Published Feb 8, 2011

Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified com…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0908

Published Feb 8, 2011

Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0526

Published Feb 8, 2011

Cross-site scripting (XSS) vulnerability in index.php in Vanilla Forums before 2.0.17 allows remote attackers to inject arbitrary web script or HTML via the Target parameter in a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,651-3,675 of 4,150 CVEsPage 147 of 166