CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:H/Au:N/C:P/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
72.6%
Heap-based buffer overflow in WinHex 12.05 SR-14, and possibly other versions, may allow attackers to execute arbitrary code via a long file name argument. NOTE: since this overflow is in the command line of an unprivileged program, it is highly likely that this is not a vulnerability.
Vendor | Product | Version | CPE |
---|---|---|---|
x-ways_software_technology_ag | winhex | 12.05_sr-14 | cpe:2.3:a:x-ways_software_technology_ag:winhex:12.05_sr-14:*:*:*:*:*:*:* |