Lucene search

K
cve[email protected]CVE-2012-0192
HistoryJan 23, 2012 - 3:55 p.m.

CVE-2012-0192

2012-01-2315:55:00
CWE-189
web.nvd.nist.gov
26
4
ibm lotus symphony
vclmi.dll
integer overflow
cve-2012-0192
nvd
security vulnerability
heap-based buffer overflow
jpeg
png
arbitrary code execution

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.11 Low

EPSS

Percentile

95.2%

Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.

Affected configurations

NVD
Node
ibmlotus_symphonyRange3.0.0.3
OR
ibmlotus_symphonyMatch1.3
OR
ibmlotus_symphonyMatch3.0.0.1
OR
ibmlotus_symphonyMatch3.0.0.2

Social References

More

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.11 Low

EPSS

Percentile

95.2%