Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-3594

Published Nov 4, 2011

The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a d…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3581

Published Nov 4, 2011

Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns before 1.6.11 allows remote attackers to cause a denial of service (crash) and possibly execute arb…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3364

Published Nov 4, 2011

Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3164

Published Nov 4, 2011

Unspecified vulnerability in HP-UX Containers (formerly HP-UX Secure Resource Partitions (SRP)) A.03.00, A.03.00.002, and A.03.01, when running with patch PHKL_42310, allows local…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1513

Published Nov 4, 2011

Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to injec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4277

Published Nov 3, 2011

Cross-site scripting (XSS) vulnerability in CourseForum ProjectForum 7.0.1.3038 allows remote attackers to inject arbitrary web script or HTML via a crafted name of an object with…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3996

Published Nov 3, 2011

The LiveData Service in CSWorks before 2.0.4115.1 allows remote attackers to cause a denial of service (service crash) via crafted TCP packets.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3987

Published Nov 3, 2011

dtsoftbus01.sys in DAEMON Tools Lite before 4.41.3, Pro Standard before 4.41.0315, and Pro Advanced before 4.41.0315 allows local users to cause a denial of service (system crash)…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3986

Published Nov 3, 2011

Cross-site scripting (XSS) vulnerability in Pligg before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4102

Published Nov 3, 2011

Heap-based buffer overflow in the erf_read_header function in wiretap/erf.c in the ERF file parser in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4101

Published Nov 3, 2011

The dissect_infiniband_common function in epan/dissectors/packet-infiniband.c in the Infiniband dissector in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote att…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4100

Published Nov 3, 2011

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4078

Published Nov 3, 2011

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a deni…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3379

Published Nov 3, 2011

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted UR…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4273

Published Nov 3, 2011

Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) the group parameter to goform/A…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4005

Published Nov 3, 2011

Cross-site request forgery (CSRF) vulnerability in the Services Ready Platform Configuration Utility web interface on the Cisco Small Business SRP521W, SRP526W, and SRP527W with f…

CVSS 9.3 · Critical

CVE-2011-3995

Published Nov 3, 2011

Unspecified vulnerability in Twilight Frontier Touhou Hisouten 1.06 and earlier allows remote attackers to cause a denial of service (daemon crash) via unknown network traffic.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 526-550 of 4,150 CVEsPage 22 of 166