Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-0733

Published Feb 1, 2011

Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header in an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0731

Published Feb 1, 2011

Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows allows remote attackers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0321

Published Feb 1, 2011

librpc.dll in nsrexecd in EMC NetWorker before 7.5 SP4, 7.5.3.x before 7.5.3.5, and 7.6.x before 7.6.1.2 does not properly mitigate the possibility of a spoofed localhost source I…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0687

Published Jan 31, 2011

Opera before 11.01 does not properly implement Wireless Application Protocol (WAP) dropdown lists, which allows user-assisted remote attackers to cause a denial of service (applic…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0686

Published Jan 31, 2011

Unspecified vulnerability in Opera before 11.01 allows remote attackers to cause a denial of service (application crash) via unknown content on a web page, as demonstrated by vkon…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0685

Published Jan 31, 2011

The Delete Private Data feature in Opera before 11.01 does not properly implement the "Clear all email account passwords" option, which might allow physically proximate attackers…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-0684

Published Jan 31, 2011

Opera before 11.01 does not properly handle redirections and unspecified other HTTP responses, which allows remote web servers to obtain sufficient access to local files to use th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0683

Published Jan 31, 2011

Opera before 11.01 does not properly restrict the use of opera: URLs, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0682

Published Jan 31, 2011

Integer truncation error in opera.dll in Opera before 11.01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML form wit…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0681

Published Jan 31, 2011

The Cascading Style Sheets (CSS) Extensions for XML implementation in Opera before 11.01 recognizes links to javascript: URLs in the -o-link property, which makes it easier for re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0413

Published Jan 31, 2011

The DHCPv6 server in ISC DHCP 4.0.x and 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1 allows remote attackers to cause a denial of service…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0680

Published Jan 31, 2011

data/WorkingMessage.java in the Mms application in Android before 2.2.2 and 2.3.x before 2.3.2 does not properly manage the draft cache, which allows remote attackers to read SMS…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0450

Published Jan 31, 2011

The downloads manager in Opera before 11.01 on Windows does not properly determine the pathname of the filesystem-viewing application, which allows user-assisted remote attackers…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4717

Published Jan 31, 2011

Multiple stack-based buffer overflows in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4716

Published Jan 31, 2011

Cross-site scripting (XSS) vulnerability in the WebPublisher component in Novell GroupWise before 8.02HP allows remote attackers to inject arbitrary web script or HTML via unspeci…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4715

Published Jan 31, 2011

Multiple directory traversal vulnerabilities in the (1) WebAccess Agent and (2) Document Viewer Agent components in Novell GroupWise before 8.02HP allow remote attackers to read a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4714

Published Jan 31, 2011

Multiple stack-based buffer overflows in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) gwpoa.exe in the Post O…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4713

Published Jan 31, 2011

Integer signedness error in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to execute arbitrary code via a signed integer va…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4712

Published Jan 31, 2011

Multiple stack-based buffer overflows in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a Conte…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 3,751-3,775 of 4,150 CVEsPage 151 of 166