Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-4173

Published Oct 24, 2011

Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authentication of administrators or moderator…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4172

Published Oct 24, 2011

Multiple cross-site scripting (XSS) vulnerabilities in KENT-WEB WEB FORUM before 5.1 allow remote attackers to inject arbitrary web script or HTML via (1) an e-mail address field…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4171

Published Oct 24, 2011

Cross-site scripting (XSS) vulnerability in content/error.jsp in IBM WebSphere ILOG Rule Team Server 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3984

Published Oct 24, 2011

Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to "web form entr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3983

Published Oct 24, 2011

Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to cookies.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3615

Published Oct 24, 2011

Multiple SQL injection vulnerabilities in Simple Machines Forum (SMF) before 1.1.15 and 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via vectors invol…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3383

Published Oct 24, 2011

Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to "the web page…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2656

Published Oct 24, 2011

Unspecified vulnerability in ZfHSrvr.exe in Novell ZENworks Handheld Management (ZHM) 7 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerab…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-2655

Published Oct 24, 2011

Unspecified vulnerability in ZfHSrvr.exe in Novell ZENworks Handheld Management (ZHM) 7 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerab…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4170

Published Oct 23, 2011

Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3635

Published Oct 23, 2011

Cross-site scripting (XSS) vulnerability in the theme_adium_append_message function in empathy-theme-adium.c in the Adium theme in libempathy-gtk in Empathy 3.2.1 and earlier allo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1478

Published Oct 23, 2011

The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset the values of certain structure…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2059

Published Oct 22, 2011

The ipv6 component in Cisco IOS before 15.1(4)M1.3 allows remote attackers to conduct fingerprinting attacks and obtain potentially sensitive information about the presence of the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2058

Published Oct 22, 2011

The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pair of dot1x enabled ports, which allows remote attackers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2057

Published Oct 22, 2011

The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle (1) a loop between a dot1x enabled port and an open-authentication dot1x enabled port an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2042

Published Oct 22, 2011

The Sybase SQL Anywhere database component in Cisco CiscoWorks Common Services 3.x and 4.x before 4.1 allows remote attackers to obtain potentially sensitive information about the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1640

Published Oct 22, 2011

The ethernet-lldp component in Cisco IOS 12.2 before 12.2(33)SXJ1 does not properly support a large number of LLDP Management Address (MA) TLVs, which allows remote attackers to c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4026

Published Oct 21, 2011

SQL injection vulnerability in thanks.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4024

Published Oct 21, 2011

Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vecto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3988

Published Oct 21, 2011

SQL injection vulnerability in data/class/SC_Query.php in EC-CUBE 2.11.0 through 2.11.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2713

Published Oct 21, 2011

oowriter in OpenOffice.org 3.3.0 and LibreOffice before 3.4.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers an ou…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2677

Published Oct 21, 2011

Cybozu Office before 8.0.0 allows remote authenticated users to bypass intended access restrictions and access sensitive information (time card and attendance) via unspecified vec…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4063

Published Oct 21, 2011

chan_sip.c in the SIP channel driver in Asterisk Open Source 1.8.x before 1.8.7.1 and 10.x before 10.0.0-rc1 does not properly initialize variables during request parsing, which a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 701-725 of 4,150 CVEsPage 29 of 166