Lucene search

K
cve[email protected]CVE-2012-5854
HistoryNov 19, 2012 - 12:10 p.m.

CVE-2012-5854

2012-11-1912:10:54
CWE-119
web.nvd.nist.gov
34
cve-2012-5854
weechat
buffer overflow
denial of service
arbitrary code execution
nvd
vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8 High

AI Score

Confidence

Low

0.112 Low

EPSS

Percentile

95.2%

Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remote attackers to cause a denial of service (crash or hang) and possibly execute arbitrary code via crafted IRC colors that are not properly decoded.

Affected configurations

NVD
Node
flashtuxweechatMatch0.3.6
OR
flashtuxweechatMatch0.3.7
OR
flashtuxweechatMatch0.3.8
OR
flashtuxweechatMatch0.3.9

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8 High

AI Score

Confidence

Low

0.112 Low

EPSS

Percentile

95.2%