Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-3654

Published Nov 9, 2011

The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly handle links from SVG mpath elements to non-SVG elements, which allows remote attacke…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3652

Published Nov 9, 2011

The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly allocate memory, which allows remote attackers to cause a denial of service (memory c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3651

Published Nov 9, 2011

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 7.0 and Thunderbird 7.0 allow remote attackers to cause a denial of service (memory corruption and ap…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3650

Published Nov 9, 2011

Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allow…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3648

Published Nov 9, 2011

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject ar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3647

Published Nov 9, 2011

The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-o…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-2449

Published Nov 8, 2011

The TextXtra module in Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2011-2448

Published Nov 8, 2011

The DIRapi library in Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors,…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2011-2447

Published Nov 8, 2011

Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2011-2446

Published Nov 8, 2011

The DIRapi library in Adobe Shockwave Player before 11.6.3.633 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors,…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2011-4415

Published Nov 8, 2011

The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the si…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3607

Published Nov 8, 2011

Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allo…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3169

Published Nov 7, 2011

Unspecified vulnerability in the SMTP service implementation in HP TCP/IP Services 5.6 and 5.7 for OpenVMS allows remote attackers to cause a denial of service via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3168

Published Nov 7, 2011

Unspecified vulnerability in the POP and IMAP service implementations in HP TCP/IP Services 5.6 and 5.7 for OpenVMS allows remote attackers to obtain sensitive information via unk…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4066

Published Nov 4, 2011

SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3991

Published Nov 4, 2011

Untrusted search path vulnerability in FFFTP 1.98a and earlier allows local users to execute arbitrary code via unspecified functions.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3989

Published Nov 4, 2011

SQL injection vulnerability in DBD::mysqlPP 0.04 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3616

Published Nov 4, 2011

The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.cesf.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 501-525 of 4,150 CVEsPage 21 of 166