CVE-2011-0011

qemu-kvm before 0.11.0 disables VNC authentication when the password is cleared, which allows remote attackers to bypass authentication and establish VNC sessions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
ADJACENT_NETWORK
HIGH
AV:A/AC:H/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
qemuqemu
𝑥
≤ 0.11.0
qemuqemu
0.1.0
qemuqemu
0.1.1
qemuqemu
0.1.2
qemuqemu
0.1.3
qemuqemu
0.1.4
qemuqemu
0.1.5
qemuqemu
0.1.6
qemuqemu
0.10.0
qemuqemu
0.10.1
qemuqemu
0.10.2
qemuqemu
0.10.3
qemuqemu
0.10.4
qemuqemu
0.10.5
qemuqemu
0.10.6
qemuqemu
0.11.0:rc0
qemuqemu
0.11.0:rc1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qemu-kvm
maverick
Fixed 0.12.5+noroms-0ubuntu7.2
released
lucid
Fixed 0.12.3+noroms-0ubuntu9.4
released
karmic
Fixed 0.11.0-0ubuntu6.4
released
hardy
dne
dapper
dne