5.1 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:H/Au:N/C:P/I:P/A:P
8.3 High
AI Score
Confidence
Low
0.004 Low
EPSS
Percentile
72.6%
Heap-based buffer overflow in WinHex 12.05 SR-14, and possibly other versions, may allow attackers to execute arbitrary code via a long file name argument. NOTE: since this overflow is in the command line of an unprivileged program, it is highly likely that this is not a vulnerability.
CPE | Name | Operator | Version |
---|---|---|---|
x-ways_software_technology_ag:winhex | x-ways software technology ag winhex | eq | 12.05_sr-14 |