Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-3269 | First vendor Publication | 2011-02-02 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to use of a function pointer in a callback mechanism. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3269 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
CPE : Common Platform Enumeration
SAINT Exploits
Description | Link |
---|---|
WebEx WRF Player buffer overflow | More info here |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
72432 | Cisco WebEx WRF File Handling Overflow Cisco WebEx is prone to an overflow condition. The WebEx Recording Format and Advanced Recording Format Players fail to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted .wrf or .arf file, a context-dependent attacker can potentially execute arbitrary code. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Cisco Webex Player .wrf stack buffer overflow RuleID : 19226 - Revision : 13 - Type : FILE-OTHER |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:06:13 |
|
2024-11-28 12:22:49 |
|
2021-05-04 12:12:19 |
|
2021-04-22 01:13:04 |
|
2020-05-23 00:26:25 |
|
2018-10-11 00:19:55 |
|
2017-08-17 09:23:06 |
|
2014-01-19 21:27:08 |
|
2013-05-10 23:31:59 |
|