CVE-2012-2418 - CERT CVE
ID CVE-2012-2418
Sažetak Heap-based buffer overflow in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a URI with a % (percent) character as its (1) last or (2) second-to-last character.
Reference
CVSS
Base: 6.8
Impact: 10.0
Exploitability:3.2
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE COMPLETE COMPLETE
CVSS vektor AV:A/AC:H/Au:N/C:C/I:C/A:C
Zadnje važnije ažuriranje 23-07-2021 - 15:12
Objavljeno 25-04-2012 - 20:55