Skip to main content

Year archive

CVEs published in 2011

Archive summary

4,150 CVEs published in 2011 — 878 Critical, 911 High, 2,100 Medium, 261 Low, 0 Unrated.

CVE-2011-3548

Published Oct 19, 2011

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3547

Published Oct 19, 2011

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3545

Published Oct 19, 2011

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier, and…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3521

Published Oct 19, 2011

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE, 7, 6 Update 27 and earlier, and 5.0 Update 31 and earlier allows remote untruste…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3516

Published Oct 19, 2011

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, when running on Windows, allows remote untrusted Java We…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4140

Published Oct 19, 2011

The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary HTTP Host headers, which allo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4139

Published Oct 19, 2011

Django before 1.2.7 and 1.3.x before 1.3.1 uses a request's HTTP Host header to construct a full URL in certain circumstances, which allows remote attackers to conduct cache poiso…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4138

Published Oct 19, 2011

The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 originally tests a URL's validity through a HEAD request, but then use…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4137

Published Oct 19, 2011

The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 relies on Python libraries that attempt access to an arbitrary URL wit…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4136

Published Oct 19, 2011

django.contrib.sessions in Django before 1.2.7 and 1.3.x before 1.3.1, when session data is stored in the cache, uses the root namespace for both session identifiers and applicati…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2323

Published Oct 18, 2011

Unspecified vulnerability in the Health Sciences - Oracle Thesaurus Management System component in Oracle Industry Applications 4.6.1 and 4.6.2 allows remote attackers to affect i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3543

Published Oct 18, 2011

Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availability, related to iSCSI DataMover (IDM).

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3542

Published Oct 18, 2011

Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability via unknown vectors related to Kernel/Performance Counter BackEnd Module (p…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3541

Published Oct 18, 2011

Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows local users to affect availability via unknown vectors r…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort
Showing 751-775 of 4,150 CVEsPage 31 of 166