CVE-2012-0897
IrfanView JPEG2000 4.3.2.0 - jp2 Stack Buffer Overflow
Severity Score
Exploit Likelihood
Affected Versions
86Public Exploits
2Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.
Desbordamiento de búfer basado en pila en el complemento JPEG2000 para IrfanView PlugIns, permite a atacantes remotos ejecutar código de su elección a través de un archivo JPEG2000 (JP2) con un marcador de segmento Quantization Default (QCD) manipulado.
Printer virtualization under VMware Workstation involves a vprintproxy.exe process launched by vmware-vmx.exe on the Host. It will receive and process EMFSPOOL files sent by a Guest on its COM1 port, if a virtual printer has been added to the VM hardware (default). Several vulnerabilities in this component allow an unprivileged Guest user to execute code on the Host.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-01-20 CVE Reserved
- 2012-01-20 CVE Published
- 2012-07-01 First Exploit
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (9)
URL | Date | SRC |
---|