{"api_version":"1","generated_at":"2026-07-23T05:32:54+00:00","cve":"CVE-2011-1065","urls":{"html":"https://cve.report/CVE-2011-1065","api":"https://cve.report/api/cve/CVE-2011-1065.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1065","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1065"},"summary":{"title":"CVE-2011-1065","description":"Multiple stack-based buffer overflows in the PIPIWebPlayer ActiveX control (PIWebPlayer.ocx) in PIPI Player 2.8.0.0 allow remote attackers to execute arbitrary code via long arguments to the (1) PlayURL or (2) PlayURLWithLocalPlayer methods.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-02-23 01:00:02","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.wooyun.org/bugs/wooyun-2010-01382","name":"http://www.wooyun.org/bugs/wooyun-2010-01382","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"皮皮播放器ActiveX控件 PlayURL（）函数溢出漏洞 | WooYun-2011-01382 | WooYun.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.wooyun.org/bugs/wooyun-2010-01383","name":"http://www.wooyun.org/bugs/wooyun-2010-01383","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"皮皮播放器ActiveX控件PlayURLWithLocalPlayer（）函数溢出漏洞 | WooYun-2011-01383 | WooYun.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65537","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65537","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/46468","name":"http://www.securityfocus.com/bid/46468","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PIPI Player 'PIPIWebPlayer.ocx' ActiveX Multiple Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/43394","name":"http://secunia.com/advisories/43394","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PIPI Player PIPIWebPlayer ActiveX Control Buffer Overflow Vulnerability - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1065","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1065","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1065","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pipi","cpe5":"pipi_player","cpe6":"2.8.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:14:27.329Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"43394","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43394"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.wooyun.org/bugs/wooyun-2010-01383"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.wooyun.org/bugs/wooyun-2010-01382"},{"name":"46468","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/46468"},{"name":"pipiplayer-activex-control-bo(65537)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65537"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-02-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple stack-based buffer overflows in the PIPIWebPlayer ActiveX control (PIWebPlayer.ocx) in PIPI Player 2.8.0.0 allow remote attackers to execute arbitrary code via long arguments to the (1) PlayURL or (2) PlayURLWithLocalPlayer methods."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"43394","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43394"},{"tags":["x_refsource_MISC"],"url":"http://www.wooyun.org/bugs/wooyun-2010-01383"},{"tags":["x_refsource_MISC"],"url":"http://www.wooyun.org/bugs/wooyun-2010-01382"},{"name":"46468","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/46468"},{"name":"pipiplayer-activex-control-bo(65537)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65537"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-1065","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple stack-based buffer overflows in the PIPIWebPlayer ActiveX control (PIWebPlayer.ocx) in PIPI Player 2.8.0.0 allow remote attackers to execute arbitrary code via long arguments to the (1) PlayURL or (2) PlayURLWithLocalPlayer methods."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"43394","refsource":"SECUNIA","url":"http://secunia.com/advisories/43394"},{"name":"http://www.wooyun.org/bugs/wooyun-2010-01383","refsource":"MISC","url":"http://www.wooyun.org/bugs/wooyun-2010-01383"},{"name":"http://www.wooyun.org/bugs/wooyun-2010-01382","refsource":"MISC","url":"http://www.wooyun.org/bugs/wooyun-2010-01382"},{"name":"46468","refsource":"BID","url":"http://www.securityfocus.com/bid/46468"},{"name":"pipiplayer-activex-control-bo(65537)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65537"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-1065","datePublished":"2011-02-22T23:00:00.000Z","dateReserved":"2011-02-22T00:00:00.000Z","dateUpdated":"2024-08-06T22:14:27.329Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-02-23 01:00:02","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:pipi:pipi_player:2.8.0.0:*:*:*:*:*:*:*","matchCriteriaId":"C2D600A1-3101-4C14-BB20-C7C682B125DF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1065","Ordinal":"1","Title":"CVE-2011-1065","CVE":"CVE-2011-1065","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1065","Ordinal":"1","NoteData":"Multiple stack-based buffer overflows in the PIPIWebPlayer ActiveX control (PIWebPlayer.ocx) in PIPI Player 2.8.0.0 allow remote attackers to execute arbitrary code via long arguments to the (1) PlayURL or (2) PlayURLWithLocalPlayer methods.","Type":"Description","Title":"CVE-2011-1065"},{"CveYear":"2011","CveId":"1065","Ordinal":"2","NoteData":"2011-02-22","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"1065","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}