Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-0903

Published Feb 7, 2011

Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitrary files and possibly have other unspecified impact via a .…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0901

Published Feb 7, 2011

Multiple stack-based buffer overflows in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions, allow user-assiste…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0900

Published Feb 7, 2011

Stack-based buffer overflow in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions, allows user-assisted remote…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0531

Published Feb 7, 2011

demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary com…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0522

Published Feb 7, 2011

The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/codec/subtitles/subsusf.c) in VideoLAN VLC Media Player 1.1 bef…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0324

Published Feb 7, 2011

Multiple heap-based buffer overflows in Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allow remote attackers to execute arbitrary code v…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0323

Published Feb 7, 2011

Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLog…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0025

Published Feb 4, 2011

IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entiti…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0784

Published Feb 4, 2011

Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code via vectors related to audio.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0783

Published Feb 4, 2011

Unspecified vulnerability in Google Chrome before 9.0.597.84 allows user-assisted remote attackers to cause a denial of service (application crash) via vectors involving a "bad vo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0782

Published Feb 4, 2011

Google Chrome before 9.0.597.84 on Mac OS X does not properly mitigate an unspecified flaw in the Mac OS X 10.5 SSL libraries, which allows remote attackers to cause a denial of s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0781

Published Feb 4, 2011

Google Chrome before 9.0.597.84 does not properly handle autofill profile merging, which has unspecified impact and remote attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0780

Published Feb 4, 2011

The PDF event handler in Google Chrome before 9.0.597.84 does not properly interact with print operations, which allows user-assisted remote attackers to cause a denial of service…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0779

Published Feb 4, 2011

Google Chrome before 9.0.597.84 does not properly handle a missing key in an extension, which allows remote attackers to cause a denial of service (application crash) via a crafte…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0778

Published Feb 4, 2011

Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0777

Published Feb 4, 2011

Use-after-free vulnerability in Google Chrome before 9.0.597.84 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0776

Published Feb 4, 2011

The sandbox implementation in Google Chrome before 9.0.597.84 on Mac OS X might allow remote attackers to obtain potentially sensitive information about local files via vectors re…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0775

Published Feb 4, 2011

pivotx/modules/module_image.php in PivotX 2.2.2 allows remote attackers to obtain sensitive information via a non-existent file in the image parameter, which reveals the installat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0774

Published Feb 4, 2011

PivotX before 2.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) includes/ping.php and (2) includes/spamping.php, which reveals the installa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0773

Published Feb 4, 2011

Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the image par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0772

Published Feb 4, 2011

Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow remote attackers to inject arbitrary web script or HTML via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0771

Published Feb 4, 2011

The Janrain Engage (formerly RPX) module 6.x-1.3 for Drupal does not validate the file for a profile image, which allows remote authenticated users to conduct cross-site scripting…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,676-3,700 of 4,150 CVEsPage 148 of 166