Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2010-4979

Published Nov 1, 2011

SQL injection vulnerability in image/view.php in CANDID allows remote attackers to execute arbitrary SQL commands via the image_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4978

Published Nov 1, 2011

Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web script or HTML via the image_id parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4977

Published Nov 1, 2011

SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the mealid parameter t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4976

Published Nov 1, 2011

Cross-site scripting (XSS) vulnerability in search/search.php in MetInfo 3.0 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter (aka Searc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4975

Published Nov 1, 2011

SQL injection vulnerability in the Techjoomla SocialAds For JomSocial (com_socialads) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the ads d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4974

Published Nov 1, 2011

SQL injection vulnerability in info.php in BrotherScripts (BS) and ScriptsFeed Auto Dealer allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4973

Published Nov 1, 2011

Cross-site scripting (XSS) vulnerability in the search feature in Campsite 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the f_search_keywords parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4972

Published Nov 1, 2011

SQL injection vulnerability in index.php in YPNinc JokeScript allows remote attackers to execute arbitrary SQL commands via the ypncat_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4970

Published Nov 1, 2011

SQL injection vulnerability in handlers/getpage.php in Wiki Web Help 0.28 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4969

Published Nov 1, 2011

SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4968

Published Nov 1, 2011

SQL injection vulnerability in the webmaster-tips.net Flash Gallery (com_wmtpic) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4223

Published Nov 1, 2011

Unspecified vulnerability in Investintech.com Absolute PDF Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4221

Published Nov 1, 2011

Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a denial of service (application crash) or possibly execute arbit…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4220

Published Nov 1, 2011

Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a denial of service (application cra…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4219

Published Nov 1, 2011

Investintech.com SlimPDF Reader does not prevent faulting-address data from affecting branch selection, which allows remote attackers to cause a denial of service (application cra…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4218

Published Nov 1, 2011

Investintech.com SlimPDF Reader does not prevent faulting-instruction data from affecting write operations, which allows remote attackers to cause a denial of service (application…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4217

Published Nov 1, 2011

Investintech.com SlimPDF Reader does not properly restrict read operations during block data moves, which allows remote attackers to cause a denial of service (application crash)…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4216

Published Nov 1, 2011

Investintech.com SlimPDF Reader does not properly restrict write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arb…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4215

Published Nov 1, 2011

SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to execute arbitrary SQL commands via th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4214

Published Nov 1, 2011

OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges via a crafted oozimsrememberme c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4064

Published Nov 1, 2011

Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4213

Published Oct 30, 2011

The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent use of the os module, which allows local users to bypass intended access restric…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 626-650 of 4,150 CVEsPage 26 of 166