CVE-2011-0651
Last modified
CVE-2011-0651 is a vulnerability of currently unknown severity. Buffer overflow in the key exchange functionality in Icon Labs Iconfidant SSL Server before 1.3.0 allows remote attackers to execute arbitrary code via a client master key packet in which the sum of unspecified length fields is greater than a certain value.. EPSS estimates a 4.89% chance of exploitation in the next 30 days.
Description
Buffer overflow in the key exchange functionality in Icon Labs Iconfidant SSL Server before 1.3.0 allows remote attackers to execute arbitrary code via a client master key packet in which the sum of unspecified length fields is greater than a certain value.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Icon-Labs | Iconfidant Ssl Server | <= 1.2.9 |
References
- http://secunia.com/advisories/42971Vendor Advisory
- http://secunia.com/advisories/42971Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-0651?
How severe is CVE-2011-0651?
How do I fix CVE-2011-0651?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-0645SQL injection vulnerability in data.php in PHPCMS 2008 V2 al…
- CVE-2011-0646SQL injection vulnerability in viewfaqs.php in PHP LOW BIDS …
- CVE-2011-0647The irccd.exe service in EMC Replication Manager Client befo…
- CVE-2011-0648Unspecified vulnerability in EMC Avamar before 5.0.4-30 allo…
- CVE-2011-0649Multiple unspecified vulnerabilities in TIBCO Rendezvous 8.2…
- CVE-2011-0650Cross-site request forgery (CSRF) vulnerability in Greenbone…
- CVE-2011-0652lnsfw1.sys 6.0.2900.5512 in Look 'n' Stop Firewall 2.06p4 an…
- CVE-2011-0653Cross-site scripting (XSS) vulnerability in Microsoft Office…
- CVE-2011-0654Integer underflow in the BowserWriteErrorLogEntry function i…
- CVE-2011-0655Microsoft PowerPoint 2007 SP2 and 2010; Office 2004, 2008, a…
- CVE-2011-0656Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010;…
- CVE-2011-0657DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and…9.8
Are you affected by CVE-2011-0651?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
