Lucene search

K
nvd[email protected]NVD:CVE-2011-2386
HistoryJun 08, 2011 - 10:36 a.m.

CVE-2011-2386

2011-06-0810:36:14
CWE-94
web.nvd.nist.gov
2

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.851

Percentile

98.6%

VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary code via a (1) vws and (2) vwr file with an invalid Type property, which triggers an untrusted pointer dereference.

Affected configurations

Nvd
Node
visiwavesite_surveyRange2.1
OR
visiwavesite_surveyMatch1.6.12
OR
visiwavesite_surveyMatch2.0.12
VendorProductVersionCPE
visiwavesite_survey*cpe:2.3:a:visiwave:site_survey:*:*:*:*:*:*:*:*
visiwavesite_survey1.6.12cpe:2.3:a:visiwave:site_survey:1.6.12:*:*:*:*:*:*:*
visiwavesite_survey2.0.12cpe:2.3:a:visiwave:site_survey:2.0.12:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.851

Percentile

98.6%