← All CVEs

CVE-2012-0985

high · 9.3

Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.00_64, 1.0.1, 2.0, and 3.0; SmartWi Connection Utility 4.7, 4.7.4, 4.8, 4.9, 4.10, and 4.11; and VAIO Easy Connect software 1.0.0 and 1.1.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the second argument of the (1) SetTmpProfileOption or (2) ConnectToNetwork method.

9.3
CVSS
13.0%
EPSS (exploit prob.)
96th
EPSS percentile
2012-06-07
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
sonysmartwi_connection_utillity4.7
sonysmartwi_connection_utillity4.7.4
sonysmartwi_connection_utillity4.8
sonysmartwi_connection_utillity4.9
sonysmartwi_connection_utillity4.10
sonysmartwi_connection_utillity4.11
sonyvaio_easy_connect1.0.0
sonyvaio_easy_connect1.1.0
sonyvaio_pc_wireless_lan_wizard1.0
sonyvaio_wireless_wizard1.00
sonyvaio_wireless_wizard1.00_64
sonyvaio_wireless_wizard1.01
sonyvaio_wireless_wizard2.0
sonyvaio_wireless_wizard3.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-0985