Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-3166

Published Nov 2, 2011

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1209.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3165

Published Nov 2, 2011

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1208.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1919

Published Nov 2, 2011

Multiple stack-based buffer overflows in GE Intelligent Platforms Proficy Applications before 4.4.1 SIM 101 and 5.x before 5.0 SIM 43 allow remote attackers to cause a denial of s…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1918

Published Nov 2, 2011

Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-5003

Published Nov 1, 2011

SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the limit parameter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5002

Published Nov 1, 2011

Cross-site scripting (XSS) vulnerability in modules/slideshowmodule/slideshow.js.php in Exponent CMS 0.97.0 allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5001

Published Nov 1, 2011

SQL injection vulnerability in view.php in esoftpro Online Contact Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4999

Published Nov 1, 2011

SQL injection vulnerability in index.php in esoftpro Online Photo Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the section parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4996

Published Nov 1, 2011

SQL injection vulnerability in ogp_show.php in esoftpro Online Guestbook Pro 5.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4995

Published Nov 1, 2011

SQL injection vulnerability in the NeoRecruit (com_neorecruit) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4994

Published Nov 1, 2011

SQL injection vulnerability in the Jobs Pro component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the detailed_results parameter to search_jobs…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4991

Published Nov 1, 2011

SQL injection vulnerability in the NinjaMonials (com_ninjamonials) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a di…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4990

Published Nov 1, 2011

SQL injection vulnerability in the Front-edit Address Book (com_addressbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid paramet…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4989

Published Nov 1, 2011

SQL injection vulnerability in main.asp in Ziggurat Farsi CMS allows remote attackers to execute arbitrary SQL commands via the grp parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4987

Published Nov 1, 2011

SQL injection vulnerability in default.asp in KMSoft Guestbook (aka GBook) allows remote attackers to execute arbitrary SQL commands via the p parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4985

Published Nov 1, 2011

Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to inject arbitrary web script or HTML via vectors involving the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4984

Published Nov 1, 2011

SQL injection vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to execute arbitrary SQL commands via vectors involving the "Enter Reference…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4983

Published Nov 1, 2011

SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4982

Published Nov 1, 2011

SQL injection vulnerability in address_book/contacts.php in My Kazaam Address & Contact Organizer allows remote attackers to execute arbitrary SQL commands via the var1 parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4981

Published Nov 1, 2011

SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4980

Published Nov 1, 2011

SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 601-625 of 4,150 CVEsPage 25 of 166