CVE-2010-3269
high · 9.3Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to use of a function pointer in a callback mechanism.
9.3
CVSS
11.4%
EPSS (exploit prob.)
96th
EPSS percentile
2011-02-02
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| cisco | webex_recording_format_player | 26.49 |
| cisco | webex_recording_format_player | 27.10 |
| cisco | webex_recording_format_player | 27.11.0.3328 |
| cisco | webex_recording_format_player | 27.12 |
| cisco | webex_recording_format_player | 27.13 |
| cisco | webex_advanced_recording_format_player | 26.49 |
| cisco | webex_advanced_recording_format_player | 27.10 |
| cisco | webex_advanced_recording_format_player | 27.11.0.3328 |
| cisco | webex_advanced_recording_format_player | 27.12 |
| cisco | webex_advanced_recording_format_player | 27.13 |
Check a specific version with /api/v1/cve/match.
References
- http://securitytracker.com/id?1025015
- http://tools.cisco.com/security/center/viewAlert.x?alertId=22016
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6913f.shtml
- http://www.coresecurity.com/content/webex-atp-and-wrf-overflow-vulnerabilities
- http://www.securityfocus.com/archive/1/516095/100/0/threaded
- http://www.securityfocus.com/bid/46075
- http://www.vupen.com/english/advisories/2011/0261
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65076
- http://securitytracker.com/id?1025015
- http://tools.cisco.com/security/center/viewAlert.x?alertId=22016
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6913f.shtml
- http://www.coresecurity.com/content/webex-atp-and-wrf-overflow-vulnerabilities
- http://www.securityfocus.com/archive/1/516095/100/0/threaded
- http://www.securityfocus.com/bid/46075
- http://www.vupen.com/english/advisories/2011/0261
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65076
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-3269