Lucene search

K
cve[email protected]CVE-2012-0278
HistoryApr 18, 2012 - 10:33 a.m.

CVE-2012-0278

2012-04-1810:33:32
CWE-119
web.nvd.nist.gov
29
cve-2012-0278
flashpix
buffer overflow
remote code execution
security vulnerability
irfanview

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.2 High

AI Score

Confidence

Low

0.221 Low

EPSS

Percentile

96.5%

Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.

Affected configurations

NVD
Node
irfanviewflashpix_pluginRange4.33
OR
irfanviewflashpix_pluginMatch4.32
AND
irfanviewirfanview

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.2 High

AI Score

Confidence

Low

0.221 Low

EPSS

Percentile

96.5%

Related for CVE-2012-0278