Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-2591

EPSS 22.68% · P96
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-2591

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple buffer overflows in the Provideo ActiveX controls allow remote attackers to execute arbitrary code via crafted input fields, as demonstrated by (1) a long strIp argument to the voice method in 2way.dll in the alarm 1.0.3.1 ActiveX control, (2) a network response to AXPlayer.ocx in the GMAXPlayer 2.0.8.2 ActiveX control, the (3) UserName or (4) Password parameter to AXPlayer.ocx in the GMAXPlayer 2.0.8.2 ActiveX control, (5) a long Id parameter to the GetString method in PAxPlayer.ocx in the PAxPlayer 3.0.0.9 ActiveX control, or (6) a long strAdr parameter to the ConnectIPCam method in PAxPlayer.ocx in the PAxPlayer 3.0.0.9 ActiveX control.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Provideo ActiveX控件多个缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Provideo提供一系列监控产品。 Provideo ActiveX控件中存在多个缓冲区溢出漏洞。远程攻击者可利用此漏洞在使用ActiveX控件的应用程序中执行任意代码,造成拒绝服务。 (1)在处理“voice()”方法时,alarm ActiveX控件(2way.dll)中存在边界错误,通过超长的“strIp”参数可造成栈缓冲区溢出; (2)从通过“URL”和“CtrlPort”对象参数指定的设备连接接收网络响应时,GMAXPlayer ActiveX控件中存在边界条件,可造成栈缓冲区溢出; (3)在
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-2591

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-2591

登录查看更多情报信息。

Same Patch Batch · n/a · 2011-08-05 · 9 CVEs total

CVE-2011-3009Ruby-lang Ruby随机数信息泄露漏洞
CVE-2011-1340Plone 'skins/plone_templates/default_error_message.pt'跨站脚本攻击漏洞
CVE-2011-2686Ruby 加密问题漏洞
CVE-2011-2705Ruby-Lang Ruby lib/securerandom.rb SecureRandom.random_bytes函数输入验证漏洞
CVE-2011-2720GLPI-Project GLPI autocompletion功能敏感信息泄露漏洞
CVE-2011-2721ClamAV libclamav matcher-hash.c功能cli_hm_scan函数Off-by-one漏洞
CVE-2011-2900Valenok Mongoose HTTP PUT请求处理漏洞
CVE-2011-3008Avaya Secure Access Link Gateway默认配置错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2011-2591

No comments yet


Leave a comment