Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-0537

Published Feb 4, 2011

Multiple directory traversal vulnerabilities in (1) languages/Language.php and (2) includes/StubObject.php in MediaWiki 1.8.0 and other versions before 1.16.2, when running on Win…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0049

Published Feb 4, 2011

Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read arbitrary files via .. (dot dot…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0047

Published Feb 4, 2011

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comment…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0694

Published Feb 4, 2011

Buffer overflow in LHA 1.14 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to "command li…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0720

Published Feb 3, 2011

Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create ar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4727

Published Feb 3, 2011

Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4726

Published Feb 3, 2011

Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors. NOTE: this might overlap CVE-2009-1669.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4725

Published Feb 3, 2011

Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4724

Published Feb 3, 2011

Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4723

Published Feb 3, 2011

Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which has unspecified impact and re…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4722

Published Feb 3, 2011

Unspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has unknown impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-5054

Published Feb 3, 2011

Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-5053

Published Feb 3, 2011

Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a cache file.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-5052

Published Feb 3, 2011

Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0451

Published Feb 3, 2011

Multiple cross-site scripting (XSS) vulnerabilities in (1) data/Smarty/templates/default/list.tpl and (2) data/Smarty/templates/default/campaign/bloc/cart_tag.tpl in EC-CUBE befor…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0757

Published Feb 2, 2011

IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows remote authenticated users to e…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0521

Published Feb 2, 2011

The dvb_ca_ioctl function in drivers/media/dvb/ttpci/av7110_ca.c in the Linux kernel before 2.6.38-rc2 does not check the sign of a certain integer field, which allows local users…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2010-3270

Published Feb 2, 2011

Stack-based buffer overflow in Cisco WebEx Meeting Center T27LB before SP21 EP3 and T27LC before SP22 allows user-assisted remote authenticated users to execute arbitrary code by…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,701-3,725 of 4,150 CVEsPage 149 of 166