Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-4502

Published Nov 22, 2011

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with…

CVSS 10.0 · Critical

CVE-2011-4501

Published Nov 22, 2011

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with…

CVSS 10.0 · Critical

CVE-2011-4498

Published Nov 21, 2011

Cross-site request forgery (CSRF) vulnerability in the web console in Zenprise Device Manager 6.x through 6.1.8 allows remote attackers to hijack the authentication of administrat…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4497

Published Nov 21, 2011

QIS_wizard.htm on the ASUS RT-N56U router with firmware before 1.0.1.4o allows remote attackers to obtain the administrator password via a flag=detect request.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-4496

Published Nov 21, 2011

Buffer overflow in Aviosoft DTV Player 1.0.1.2 allows remote attackers to execute arbitrary code via a crafted .plf (aka playlist) file.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4040

Published Nov 21, 2011

Buffer overflow in MiniSmtp 3.0.11818 in NJStar Communicator allows remote attackers to execute arbitrary code via a crafted packet.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4465

Published Nov 19, 2011

Cross-site scripting (XSS) vulnerability in IBM Lotus Mobile Connect (LMC) 6.1.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden red…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4404

Published Nov 19, 2011

The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attacker…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4311

Published Nov 19, 2011

ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4159

Published Nov 19, 2011

Unspecified vulnerability in System Administration Manager (SAM) in EMS before A.04.20.11.04_01 on HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges via…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3849

Published Nov 19, 2011

Unspecified vulnerability in dxserver before 6279 in CA Directory 8.1 and CA Directory r12 before SP7 CR1 allows remote attackers to cause a denial of service (daemon crash) via a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3900

Published Nov 17, 2011

Google V8, as used in Google Chrome before 15.0.874.121, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that tr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4122

Published Nov 17, 2011

Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4096

Published Nov 17, 2011

The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4073

Published Nov 17, 2011

Use-after-free vulnerability in the cryptographic helper handler functionality in Openswan 2.3.0 through 2.6.36 allows remote authenticated users to cause a denial of service (plu…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3646

Published Nov 17, 2011

phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to obtain sensitive information via an array-typed js_frame parameter to phpmyadmin.css.php, which reve…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3627

Published Nov 17, 2011

The bytecode engine in ClamAV before 0.97.3 allows remote attackers to cause a denial of service (crash) via vectors related to "recursion level" and (1) libclamav/bytecode.c and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3380

Published Nov 17, 2011

Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2770

Published Nov 17, 2011

Cross-site scripting (XSS) vulnerability in man2html.cgi.c in man2html 1.6, and possibly other version, allows remote attackers to inject arbitrary web script or HTML via unspecif…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4156

Published Nov 16, 2011

Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0x and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4155

Published Nov 16, 2011

Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0x and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 426-450 of 4,150 CVEsPage 18 of 166