LiveActive security incident?Get immediate response
CVE archive

January 2011

Browse CVE records published in January 2011, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 396 matching CVEs · Page 5 of 8.

Unknown · CVSS Not scored

CVE-2011-3937: The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x before 0.7.12, 0.8.x before 0.8.11, and unspecified...

The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x before 0.7.12, 0.8.x before 0.8.11, and unspecified versions before 0.10, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 has unspecified impact and attack vectors related to "width/height changing with frame threads."

Published Jan 5, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-3667: The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x be...

The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when createemailregexp is not empty, does not properly handle user_can_create_account settings, which allows remote attackers to create user accounts by leveraging a token contained in an e-mail message.

Published Jan 2, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-3657: Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x...

Multiple cross-site scripting (XSS) vulnerabilities in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, and 4.1.x through 4.1.3, when debug mode is used, allow remote attackers to inject arbitrary web script or HTML via vectors involving a (1) tabular report, (2) graphical report, or (3) new chart.

Published Jan 2, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-3571: Unspecified vulnerability in the Virtual Desktop Infrastructure (VDI) component in Oracle Virtualization 3....

Unspecified vulnerability in the Virtual Desktop Infrastructure (VDI) component in Oracle Virtualization 3.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Session. NOTE: this CVE identifier was accidentally used for a Concurrency issue in Java Runtime Environment, but that issue has been reassigned to CVE-2012-0507.

Published Jan 18, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-3478: The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywher...

The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), does not properly filter login and authentication data, which allows remote attackers to execute arbitrary code via a crafted session on TCP port 5631.

Published Jan 25, 2012 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2011-3375: Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and rec...

Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.

Published Jan 19, 2012 · Updated Aug 6, 2024