← All CVEs

CVE-2012-2175

high · 9.3

Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a long argument.

9.3
CVSS
29.4%
EPSS (exploit prob.)
98th
EPSS percentile
2012-06-20
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
ibmlotus_inotes8.5.0.0
ibmlotus_inotes8.5.0.1
ibmlotus_inotes8.5.1.0
ibmlotus_inotes8.5.1.1
ibmlotus_inotes8.5.1.2
ibmlotus_inotes8.5.1.3
ibmlotus_inotes8.5.1.4
ibmlotus_inotes8.5.1.5
ibmlotus_inotes8.5.2.0
ibmlotus_inotes8.5.2.1
ibmlotus_inotes8.5.2.2
ibmlotus_inotes8.5.2.3
ibmlotus_inotes8.5.3.0
ibmlotus_inotes8.5.3.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-2175