Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2010-4711

Published Jan 31, 2011

Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to execute arbitrary code via a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4643

Published Jan 28, 2011

Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-2779

Published Jan 28, 2011

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2778

Published Jan 28, 2011

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2777

Published Jan 28, 2011

Stack-based buffer overflow in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote at…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0679

Published Jan 28, 2011

IBM WebSphere Portal 6.0.1.1 through 7.0.0.0, as used in IBM Lotus Web Content Management (WCM) and IBM Lotus Quickr for WebSphere Portal, allows remote attackers to obtain sensit…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0678

Published Jan 28, 2011

Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code by uploading an executable fil…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0275

Published Jan 28, 2011

Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4710

Published Jan 28, 2011

Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4326

Published Jan 28, 2011

Multiple buffer overflows in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via variables in a VC…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4325

Published Jan 28, 2011

Buffer overflow in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP2 allows remote attackers to execute arbitrary code via a crafted TZID variable i…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0652

Published Jan 28, 2011

lnsfw1.sys 6.0.2900.5512 in Look 'n' Stop Firewall 2.06p4 and 2.07 allows local users to cause a denial of service (crash) via a crafted 0x80000064 IOCTL request that triggers an…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-0651

Published Jan 28, 2011

Buffer overflow in the key exchange functionality in Icon Labs Iconfidant SSL Server before 1.3.0 allows remote attackers to execute arbitrary code via a client master key packet…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0650

Published Jan 28, 2011

Cross-site request forgery (CSRF) vulnerability in Greenbone Security Assistant (GSA) before 2.0+rc3 allows remote attackers to hijack the authentication of users for requests tha…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0520

Published Jan 28, 2011

The compress_add_dlabel_points function in dns/Compress.c in MaraDNS 1.4.03, 1.4.05, and probably other versions allows remote attackers to cause a denial of service (segmentation…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 3,776-3,800 of 4,150 CVEsPage 152 of 166