CVE-2011-4004
Summary
| CVE | CVE-2011-4004 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-10-27 21:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Buffer overflow in the ATAS32 processing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute arbitrary code via a crafted WRF file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Webex Recording Format Player | 26 | All | All | All |
| Application | Cisco | Webex Recording Format Player | 27 | All | All | All |
| Application | Cisco | Webex Recording Format Player | 27.10 | All | All | All |
| Application | Cisco | Webex Recording Format Player | 27.12 | All | All | All |
| Application | Cisco | Webex Recording Format Player | 27.13 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Buffer Overflow Vulnerabilities in the Cisco WebEx Player | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.