# CVE-2011-10034

## Summary

- **CVE ID:** CVE-2011-10034
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-416
- **Published:** Nov 12, 2025
- **Last Modified:** May 14, 2026

## Description

AUTOMGEN versions up to and including 8.0.0.7 (also referenced as 8.022) contain a vulnerability in that project file handling frees an object and subsequently dereferences the stale pointer when processing certain malformed fields. The dangling-pointer use enables an attacker to influence an indirect call through attacker-controlled memory, resulting in denial-of-service. In some conditions, remote code execution may be possible.

## Affected Products

- IRAI — AUTOMGEN (0)

## References

- [CNA](https://www.exploit-db.com/exploits/17964)
- [CNA](https://en.iraifrance.com/automgen)
- [CNA](https://www.vulncheck.com/advisories/irai-automgen-use-after-free-remote-dos)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.67%
- **EPSS Percentile:** 71.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._