CVE-2012-1336
https://notcve.org/view.php?id=CVE-2012-1336
Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP10, and T27 LD before SP32 CP1 allows remote attackers to execute arbitrary code via a crafted WRF file, a different vulnerability than CVE-2012-1335 and CVE-2012-1337. Desbordamiento de bufer en Cisco WebEx Recording Format (WRF) player vT27 L hasta vSP11 vEP26, vT27 LB hasta vSP21 vEP10, vT27 LC anteriores a vSP25 vEP10, and vT27 LD anteriores a vSP32 CP1 permiten a atacantes remotos ejecutar código de su elección a través de un fichero WRF modificado, es una vulnerabilidad diferente a CVE-2012-1335 y CVE-2012-1337. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120404-webex http://www.securitytracker.com/id?1026888 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-1337
https://notcve.org/view.php?id=CVE-2012-1337
Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP10, and T27 LD before SP32 CP1 allows remote attackers to execute arbitrary code via a crafted WRF file, a different vulnerability than CVE-2012-1335 and CVE-2012-1336. Desbordamiento de bufer en Cisco WebEx Recording Format (WRF) player vT27 L y versiones vSP11 EP26, vT27 LB hasta vSP21 vEP10, vT27 LC anteriores a vSP25 vEP10, y vT27 LD anteriores a vSP32 CP1 permite a atacantes remotos ejecutar código de su elección a través de un fichero WRF modificado, es una vulneravilidad diferente a CVE-2012-1335 y CVE-2012-1336. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120404-webex http://www.securitytracker.com/id?1026888 https://exchange.xforce.ibmcloud.com/vulnerabilities/74606 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2011-3319 – Cisco WebEx Player WRF Type 0 Parsing Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2011-3319
Buffer overflow in the WRF parsing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute arbitrary code via a crafted WRF file. Desbordamiento de búfer en la funcionalidad de parseo WRF en Cisco WebEx Recording Format (WRF) player T26 anterior a SP49 EP40 y T27 anterior a SP28, permite a atacantes remotos ejecutar código arbitrario mediante un fichero WRF manipulado. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cisco WebEx Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within atdl2006.dll. The vulnerability is caused by lack of validation when parsing WRF files. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-webex • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2011-4004 – Cisco WebEx Player ATAS32.DLL linesProcessed Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2011-4004
Buffer overflow in the ATAS32 processing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute arbitrary code via a crafted WRF file. Desbordamiento de búfer en la funcionalidad de procesamiento de ATAS32 en Cisco WebEx Recording Format (WRF) T26 player anterior a EP40 SP49 y SP28 anterior a T27 permite a atacantes remotos ejecutar código arbitrario a través de un archivo modificado WRF. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cisco WebEx Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists in ATAS32.DLL during the parsing of values defined within the WRF file format. The vulnerable code trusts the linesProcessed value from the file, and uses it in some logic to determine the destination pointer for a memcpy. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-webex • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2010-3043
https://notcve.org/view.php?id=CVE-2010-3043
Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, a different vulnerability than CVE-2010-3041, CVE-2010-3042, and CVE-2010-3044. Múltiples desbordamientos de búfer en Cisco WebEx Recording Format (WRF) y Advanced Recording Format (ARF) Players T27LB anteriores a SP21 EP3 y T27LC anteriores a SP22, permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) o ejecutar código de su elección mediante ficheros (1) .wrf or (2) .arf manipulados, es una vulnerabilidad distinta a CVE-2010-3041, CVE-2010-3042, y CVE-2010-3044. • http://securitytracker.com/id?1025016 http://tools.cisco.com/security/center/viewAlert.x?alertId=22016 http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6913f.shtml http://www.securityfocus.com/bid/46075 https://exchange.xforce.ibmcloud.com/vulnerabilities/65074 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •