Lucene search

K
cve[email protected]CVE-2012-0804
HistoryMay 29, 2012 - 8:55 p.m.

CVE-2012-0804

2012-05-2920:55:06
CWE-119
web.nvd.nist.gov
80
cve-2012-0804
buffer overflow
denial of service
remote code execution
cvs 1.11
cvs 1.12
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

81.1%

Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.

Affected configurations

NVD
Node
cvscvsMatch1.11
OR
cvscvsMatch1.12
CPENameOperatorVersion
cvs:cvscvseq1.11
cvs:cvscvseq1.12

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

81.1%