Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-1516

Published Nov 15, 2011

The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all created processes, which allows re…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7303

Published Nov 15, 2011

The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attackers to access network resource…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4118

Published Nov 15, 2011

Mahara before 1.4.1, when MNet (aka the Moodle network feature) is used, allows remote authenticated users to gain privileges via a jump to an XMLRPC target.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2774

Published Nov 15, 2011

The "Reply to message" feature in Mahara 1.3.x and 1.4.x before 1.4.1 allows remote authenticated users to read the messages of a different user via a modified replyto parameter.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2773

Published Nov 15, 2011

Cross-site request forgery (CSRF) vulnerability in Mahara before 1.4.1 allows remote attackers to hijack the authentication of administrators for requests that add a user to an in…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2772

Published Nov 15, 2011

The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of ser…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2771

Published Nov 15, 2011

Multiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) URI attributes…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4435

Published Nov 11, 2011

The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent directory browsing, which allo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3376

Published Nov 11, 2011

org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1375

Published Nov 11, 2011

IBM AIX 6.1 and 7.1 does not restrict the wpar_limits_config and wpar_limits_modify system calls, which allows local users to cause a denial of service (system crash) via a crafte…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3442

Published Nov 11, 2011

The kernel in Apple iOS before 5.0.1 does not ensure the validity of flag combinations for an mmap system call, which allows local users to execute arbitrary unsigned code via a c…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3441

Published Nov 11, 2011

libinfo in Apple iOS before 5.0.1 does not properly formulate domain-name queries, which allows remote attackers to obtain sensitive information via a crafted DNS hostname.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3440

Published Nov 11, 2011

The Passcode Lock feature in Apple iOS before 5.0.1 on the iPad 2 does not properly implement the locked state, which allows physically proximate attackers to access data by openi…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort
Showing 451-475 of 4,150 CVEsPage 19 of 166