Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-4212

Published Oct 30, 2011

The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent os.popen calls, which allows local users to bypass intended access restrictions…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4211

Published Oct 30, 2011

The FakeFile implementation in the sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly control the opening of files, which allows local users to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1364

Published Oct 30, 2011

Cross-site request forgery (CSRF) vulnerability in _ah/admin/interactive/execute (aka the Interactive Console) in the SDK Console (aka Admin Console) in the Google App Engine Pyth…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0905

Published Oct 30, 2011

IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations o…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0900

Published Oct 30, 2011

Heap-based buffer overflow in the client in IBM WebSphere MQ 6.0 before 6.0.2.7 and 7.0 before 7.0.1.0 allows local users to gain privileges via crafted SSL information in a Clien…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1367

Published Oct 30, 2011

Unspecified vulnerability in the File Load feature in IBM Rational AppScan Standard and Express 7.8.x, 7.9.x, and 8.0.x before 8.0.0.3 allows remote attackers to execute arbitrary…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1366

Published Oct 30, 2011

Unspecified vulnerability in the Import feature in IBM Rational AppScan Enterprise and AppScan Reporting Console 5.2 through 7.9.x and 8.x before 8.0.1.1 allows remote attackers t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2748

Published Oct 30, 2011

Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2747

Published Oct 30, 2011

The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1370

Published Oct 29, 2011

The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authentication requirement, which al…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1368

Published Oct 29, 2011

The JavaServer Faces (JSF) application functionality in IBM WebSphere Application Server 8.x before 8.0.0.1 does not properly handle requests, which allows remote attackers to rea…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0780

Published Oct 29, 2011

IBM WebSphere MQ 7.x before 7.0.1.4 allows remote attackers to cause a denial of service (disk consumption) via multiple connection attempts to a stopped queue manager.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2830

Published Oct 28, 2011

Google V8, as used in Google Chrome before 14.0.835.163, does not properly implement script object wrappers, which allows remote attackers to cause a denial of service (applicatio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1371

Published Oct 28, 2011

Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to inject arbitrary web script or HTML via vecto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1360

Published Oct 28, 2011

Multiple cross-site scripting (XSS) vulnerabilities in IBM HTTP Server 2.0.47 and earlier, as used in WebSphere Application Server and other products, allow remote attackers to in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4004

Published Oct 27, 2011

Buffer overflow in the ATAS32 processing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3319

Published Oct 27, 2011

Buffer overflow in the WRF parsing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute arbit…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 651-675 of 4,150 CVEsPage 27 of 166