Lucene search

K
cve[email protected]CVE-2012-2175
HistoryJun 20, 2012 - 10:27 a.m.

CVE-2012-2175

2012-06-2010:27:28
CWE-119
web.nvd.nist.gov
116
cve-2012-2175
buffer overflow
activex control
dwa85w.dll
ibm lotus inotes
remote code execution
security vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.97 High

EPSS

Percentile

99.7%

Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a long argument.

Affected configurations

NVD
Node
ibmlotus_inotesMatch8.5.0.0
OR
ibmlotus_inotesMatch8.5.0.1
OR
ibmlotus_inotesMatch8.5.1.0
OR
ibmlotus_inotesMatch8.5.1.1
OR
ibmlotus_inotesMatch8.5.1.2
OR
ibmlotus_inotesMatch8.5.1.3
OR
ibmlotus_inotesMatch8.5.1.4
OR
ibmlotus_inotesMatch8.5.1.5
OR
ibmlotus_inotesMatch8.5.2.0
OR
ibmlotus_inotesMatch8.5.2.1
OR
ibmlotus_inotesMatch8.5.2.2
OR
ibmlotus_inotesMatch8.5.2.3
OR
ibmlotus_inotesMatch8.5.3.0
OR
ibmlotus_inotesMatch8.5.3.1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.97 High

EPSS

Percentile

99.7%