CVE-2011-2386

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
08/06/2011
Last modified:
11/04/2025

Description

VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary code via a (1) vws and (2) vwr file with an invalid Type property, which triggers an untrusted pointer dereference.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:visiwave:site_survey:*:*:*:*:*:*:*:* 2.1 (including)
cpe:2.3:a:visiwave:site_survey:1.6.12:*:*:*:*:*:*:*
cpe:2.3:a:visiwave:site_survey:2.0.12:*:*:*:*:*:*:*