Lucene search

K
cveMitreCVE-2012-5324
HistoryOct 08, 2012 - 8:55 p.m.

CVE-2012-5324

2012-10-0820:55:01
CWE-119
mitre
web.nvd.nist.gov
22
cve-2012-5324
buffer overflow
pdf printer preferences
activex control
pdfxctrl.dll
tracker software pdf-xchange
remote code execution
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.26

Percentile

96.7%

Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter to the InitFromRegistry function.

Affected configurations

Nvd
Node
tracker-softwarepdf-xchangeMatch3.60.0128
VendorProductVersionCPE
tracker-softwarepdf-xchange3.60.0128cpe:2.3:a:tracker-software:pdf-xchange:3.60.0128:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.26

Percentile

96.7%

Related for CVE-2012-5324