CVE-2011-0331
UnknownEPSS 4.49%
Last modified
CVE-2011-0331 is a vulnerability of currently unknown severity. Use-after-free vulnerability in the addOSPLext method in the Honeywell ScanServer ActiveX control 780.0.20.5 allows remote attackers to execute arbitrary code via a crafted HTML document.. EPSS estimates a 4.49% chance of exploitation in the next 30 days.
Description
Use-after-free vulnerability in the addOSPLext method in the Honeywell ScanServer ActiveX control 780.0.20.5 allows remote attackers to execute arbitrary code via a crafted HTML document.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Honeywell | Scanserver Activex Control | 780.0.20.5 |
References
- http://secunia.com/advisories/43360Vendor Advisory
- http://secunia.com/secunia_research/2011-22/Vendor Advisory
- http://secunia.com/advisories/43360Vendor Advisory
- http://secunia.com/secunia_research/2011-22/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-0331?
Use-after-free vulnerability in the addOSPLext method in the Honeywell ScanServer ActiveX control 780.0.20.5 allows remote attackers to execute arbitrary code via a crafted HTML document.
How severe is CVE-2011-0331?
Severity scoring for CVE-2011-0331 is pending analysis. The EPSS model estimates a 4.49% probability of exploitation in the next 30 days.
How do I fix CVE-2011-0331?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-0321librpc.dll in nsrexecd in EMC NetWorker before 7.5 SP4, 7.5.…
- CVE-2011-0322Unspecified vulnerability in EMC RSA Access Manager Server 5…
- CVE-2011-0323Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly…
- CVE-2011-0324Multiple heap-based buffer overflows in Topaz Systems SigPlu…
- CVE-2011-0329Directory traversal vulnerability in the GetData method in t…
- CVE-2011-0330The Dell DellSystemLite.Scanner ActiveX control in DellSyste…
- CVE-2011-0332Integer overflow in Foxit Reader before 4.3.1.0218 and Foxit…
- CVE-2011-0333Heap-based buffer overflow in the NgwiCalVTimeZoneBody::Pars…
- CVE-2011-0334Stack-based buffer overflow in gwia.exe in GroupWise Interne…
- CVE-2011-0335Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allow…
- CVE-2011-0340Multiple buffer overflows in the ISSymbol ActiveX control in…
- CVE-2011-0341Stack-based buffer overflow in the pdfmoz_onmouse function i…
Are you affected by CVE-2011-0331?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
