Lucene search

K
cveMitreCVE-2012-3797
HistoryJun 25, 2012 - 5:55 p.m.

CVE-2012-3797

2012-06-2517:55:01
CWE-119
mitre
web.nvd.nist.gov
25
cve-2012-3797
pro-face
wingp
pc runtime
proservr.exe
pro-server
denial of service
heap memory corruption
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

High

EPSS

0.041

Percentile

92.2%

Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, does not properly check packet sizes before reusing packet memory buffers, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a short crafted packet with a certain opcode.

Affected configurations

Nvd
Node
pro-facepro-server_exRange1.30.000
OR
pro-facepro-server_exMatch1.21.000
OR
pro-facepro-server_exMatch1.23.000
OR
pro-facepro-server_exMatch1.24.200
OR
pro-facewingp_pc_runtimeRange3.1.00
VendorProductVersionCPE
pro-facepro-server_ex*cpe:2.3:a:pro-face:pro-server_ex:*:*:*:*:*:*:*:*
pro-facepro-server_ex1.21.000cpe:2.3:a:pro-face:pro-server_ex:1.21.000:*:*:*:*:*:*:*
pro-facepro-server_ex1.23.000cpe:2.3:a:pro-face:pro-server_ex:1.23.000:*:*:*:*:*:*:*
pro-facepro-server_ex1.24.200cpe:2.3:a:pro-face:pro-server_ex:1.24.200:*:*:*:*:*:*:*
pro-facewingp_pc_runtime*cpe:2.3:a:pro-face:wingp_pc_runtime:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

High

EPSS

0.041

Percentile

92.2%

Related for CVE-2012-3797