Lucene search

K
cve[email protected]CVE-2013-0501
HistoryApr 12, 2013 - 7:55 p.m.

CVE-2013-0501

2013-04-1219:55:01
CWE-264
web.nvd.nist.gov
16
cve-2013-0501
edrawsoft
edoffice.edofficectrl.1
activex control
remote code execution
file read
ibm cognos disclosure management
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.9 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.2%

The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.

Affected configurations

NVD
Node
ibmcognos_disclosure_managementMatch10.2.0

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.9 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.2%

Related for CVE-2013-0501