9.3
CVE-2014-2136
- EPSS 4.27%
- Veröffentlicht 08.05.2014 10:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .arf file, aka Bug IDs CSCui72223, CSCul01163, and CSCul01166.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Webex Advanced Recording Format Player Versiont27ld
Cisco ≫ Webex Advanced Recording Format Player Versiont28
Cisco ≫ Webex Advanced Recording Format Player Versiont29
Cisco ≫ Webex Recording Format Player Versiont27ld
Cisco ≫ Webex Recording Format Player Versiont28
Cisco ≫ Webex Recording Format Player Versiont29
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 4.27% | 0.877 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.