CVE-2011-0011

EUVD-2011-0038
qemu-kvm before 0.11.0 disables VNC authentication when the password is cleared, which allows remote attackers to bypass authentication and establish VNC sessions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
ADJACENT_NETWORK
HIGH
AV:A/AC:H/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
Affected Products (NVD)
VendorProductVersion
qemuqemu
𝑥
≤ 0.11.0
qemuqemu
0.1.0
qemuqemu
0.1.1
qemuqemu
0.1.2
qemuqemu
0.1.3
qemuqemu
0.1.4
qemuqemu
0.1.5
qemuqemu
0.1.6
qemuqemu
0.10.0
qemuqemu
0.10.1
qemuqemu
0.10.2
qemuqemu
0.10.3
qemuqemu
0.10.4
qemuqemu
0.10.5
qemuqemu
0.10.6
qemuqemu
0.11.0:rc0
qemuqemu
0.11.0:rc1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qemu-kvm
dapper
dne
hardy
dne
karmic
Fixed 0.11.0-0ubuntu6.4
released
lucid
Fixed 0.12.3+noroms-0ubuntu9.4
released
maverick
Fixed 0.12.5+noroms-0ubuntu7.2
released