Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-4079

Published Oct 27, 2011

Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and earlier allows remote attackers to cause a denial of service (slapd crash) via a zero-length string tha…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3871

Published Oct 27, 2011

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or tri…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3870

Published Oct 27, 2011

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3869

Published Oct 27, 2011

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3848

Published Oct 27, 2011

Directory traversal vulnerability in Puppet 2.6.x before 2.6.10 and 2.7.x before 2.7.4 allows remote attackers to write X.509 Certificate Signing Request (CSR) to arbitrary locati…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3891

Published Oct 25, 2011

Google Chrome before 15.0.874.102 does not properly restrict access to internal Google V8 functions, which allows remote attackers to cause a denial of service or possibly have un…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3890

Published Oct 25, 2011

Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relate…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3889

Published Oct 25, 2011

Heap-based buffer overflow in the Web Audio implementation in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3886

Published Oct 25, 2011

Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3884

Published Oct 25, 2011

Google Chrome before 15.0.874.102 does not properly address timing issues during DOM traversal, which allows remote attackers to cause a denial of service or possibly have unspeci…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3883

Published Oct 25, 2011

Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relate…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3882

Published Oct 25, 2011

Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relate…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3880

Published Oct 25, 2011

Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact and remote attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3879

Published Oct 25, 2011

Google Chrome before 15.0.874.102 does not prevent redirects to chrome: URLs, which has unspecified impact and remote attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3878

Published Oct 25, 2011

Race condition in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to worker pr…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3877

Published Oct 25, 2011

Cross-site scripting (XSS) vulnerability in the appcache internals page in Google Chrome before 15.0.874.102 allows remote attackers to inject arbitrary web script or HTML via uns…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3876

Published Oct 25, 2011

Google Chrome before 15.0.874.102 does not properly handle downloading files that have whitespace characters at the end of a filename, which has unspecified impact and user-assist…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3875

Published Oct 25, 2011

Google Chrome before 15.0.874.102 does not properly handle drag and drop operations on URL strings, which allows user-assisted remote attackers to spoof the URL bar via unspecifie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 676-700 of 4,150 CVEsPage 28 of 166