Lucene search

K
cveIbmCVE-2012-5945
HistoryApr 30, 2013 - 3:33 a.m.

CVE-2012-5945

2013-04-3003:33:29
CWE-119
ibm
web.nvd.nist.gov
95
security
vulnerability
buffer overflow
ibm spss samplepower 3.0
activex control
cve-2012-5945

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.953

Percentile

99.4%

Multiple buffer overflows in the Vsflex8l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allow remote attackers to execute arbitrary code via a long (1) ComboList or (2) ColComboList property value.

Affected configurations

Nvd
Node
ibmspss_samplepowerMatch3.0.0.0
VendorProductVersionCPE
ibmspss_samplepower3.0.0.0cpe:2.3:a:ibm:spss_samplepower:3.0.0.0:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.953

Percentile

99.4%