Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-2175

EPSS 66.50% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2012-2175

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a long argument.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM Lotus iNotes Upload Module ActiveX控件缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM Lotus iNotes(又名IBM iNotes)是美国IBM公司的一套基于Web的电子邮件软件。该软件可帮助不同类型的用户(在线用户和离线用户)有效地管理关键业务信息和协作。 IBM Lotus iNotes Upload Module ActiveX控件中存在漏洞,该漏洞源于dwa85W.dll模块中的一个错误。攻击者可利用该漏洞通过分配一个过长的字符串到"Attachment_Times"属性导致缓冲区溢出,操控用户系统。成功利用该漏洞可允许攻击者执行任意代码。IBM Lotus iNot
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2012-2175

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2012-2175

Please Login to view more intelligence information

Same Patch Batch · n/a · 2012-06-20 · 20 CVEs total

CVE-2012-0716IBM WebSphere Application Server跨站脚本漏洞
CVE-2012-2192IBM AIX ‘socketpair()’ 拒绝服务漏洞
CVE-2012-2180IBM DB2 DRDA模块拒绝服务漏洞
CVE-2012-2174IBM Lotus Notes “notes” URI处理器任意代码执行漏洞
CVE-2012-2173IBM Security AppScan Source敏感信息漏洞
CVE-2012-2170IBM WebSphere Application Server信息泄漏漏洞
CVE-2012-2161IBM SPSS Data Collection跨站脚本漏洞
CVE-2012-2159IBM SPSS Data Collection开放重定向漏洞
CVE-2012-0720IBM WebSphere Application Server跨站脚本漏洞
CVE-2012-0717IBM WebSphere Application Server授权问题漏洞
CVE-2012-2493多个平台下的Cisco AnyConnect Secure Mobility Client任意代码执行漏洞
CVE-2012-3790Adiscon LogAnalyzer ‘highlight’参数跨站脚本漏洞
CVE-2011-5095OpenSSL ‘Diffie-Hellman key-exchange’安全漏洞
CVE-2011-1923PolarSSL安全绕过漏洞
CVE-2012-3063Cisco ACE安全绕过漏洞
CVE-2012-3058Cisco ASA/Catalyst ASASM拒绝服务漏洞
CVE-2012-2496Cisco AnyConnect Secure Mobility Client 代码注入漏洞
CVE-2012-2495Cisco AnyConnect Secure Mobility Client/Secure Desktop安全漏洞
CVE-2012-2494Cisco AnyConnect Secure Mobility Client ‘WebLaunch’功能安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2012-2175

No comments yet


Leave a comment