Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-0755

Published Feb 2, 2011

Integer overflow in the mt_rand function in PHP before 5.3.4 might make it easier for context-dependent attackers to predict the return values by leveraging a script's use of a la…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0754

Published Feb 2, 2011

The SplFileInfo::getType function in the Standard PHP Library (SPL) extension in PHP before 5.3.4 on Windows does not properly detect symbolic links, which might make it easier fo…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0753

Published Feb 2, 2011

Race condition in the PCNTL extension in PHP before 5.3.4, when a user-defined signal handler exists, might allow context-dependent attackers to cause a denial of service (memory…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0752

Published Feb 2, 2011

The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0742

Published Feb 2, 2011

Buffer overflow in ZfHIPCND.exe in Novell ZENworks Handheld Management 7.0 allows remote attackers to execute arbitrary code via a crafted IP Conduit packet to TCP port 2400.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0741

Published Feb 2, 2011

Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) installer or (2) image…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0740

Published Feb 2, 2011

Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0739

Published Feb 2, 2011

The deliver function in the sendmail delivery agent (lib/mail/network/delivery_methods/sendmail.rb) in Ruby Mail gem 2.2.14 and earlier allows remote attackers to execute arbitrar…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0738

Published Feb 2, 2011

MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.509 certificate for the myproxy-server,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0276

Published Feb 2, 2011

HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attacke…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0017

Published Feb 2, 2011

The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4652

Published Feb 2, 2011

Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of se…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4015

Published Feb 2, 2011

Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3930

Published Feb 2, 2011

Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via unspecified vectors related to AjaxSearch, a different vu…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3929

Published Feb 2, 2011

SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-3854

Published Feb 2, 2011

Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3719

Published Feb 2, 2011

Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attackers to execute arbitrary code v…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4721

Published Feb 1, 2011

SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4720

Published Feb 1, 2011

SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component before 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4719

Published Feb 1, 2011

Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4718

Published Feb 1, 2011

Multiple cross-site scripting (XSS) vulnerabilities in the Lyftenbloggie (com_lyftenbloggie) component 1.1.0 for Joomla! allow remote attackers to inject arbitrary web script or H…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0737

Published Feb 1, 2011

Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the installation path in an error m…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0736

Published Feb 1, 2011

Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0735

Published Feb 1, 2011

Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via vectors involving a "tag script."

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0734

Published Feb 1, 2011

Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via an id parameter containing a Java…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,726-3,750 of 4,150 CVEsPage 150 of 166