CVE-2010-3269
published 2011-02-02CVE-2010-3269: Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC…
PriorityP349critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
11.41%
95.5th percentile
Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to use of a function pointer in a callback mechanism.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_advanced_recording_format_player | — | — |
| cisco | webex_advanced_recording_format_player | — | — |
| cisco | webex_advanced_recording_format_player | — | — |
| cisco | webex_advanced_recording_format_player | — | — |
| cisco | webex_advanced_recording_format_player | — | — |
| cisco | webex_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h743-8964-67h5: Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and
ghsa_unreviewed·2022-05-14
CVE-2010-3269 [HIGH] CWE-119 GHSA-h743-8964-67h5: Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and
Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to use of a function pointer in a callback mechanism.
Cisco
Multiple Cisco WebEx Player Vulnerabilities
vendor_cisco·2011-02-01·CVSS 9.3
CVE-2010-3041 [CRITICAL] CWE-94 Multiple Cisco WebEx Player Vulnerabilities
Multiple Cisco WebEx Player Vulnerabilities
Multiple buffer overflow vulnerabilities exist in the Cisco WebEx
Recording Format (WRF) and Advanced Recording Format (ARF) Players. In some
cases, exploitation of the vulnerabilities could allow a remote attacker to
execute arbitrary code on the system of a targeted user.
The Cisco WebEx Players are applications that are used to
play back WebEx meeting recordings that have been recorded on the computer of
an on-line meeting attendee. The players can be automatically installed when
the user accesses a recording file that is hosted on a WebEx server. The player
can also be manually installed for offline playback after downloading the
application from www.webex.com
.
If the WebEx recording player was automatically installed,
it will be automati
Cisco
Multiple Cisco WebEx Player Vulnerabilities
vendor_cisco
CVE-2010-3269 Multiple Cisco WebEx Player Vulnerabilities
CVE-2010-3269: Multiple Cisco WebEx Player Vulnerabilities
Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players. In some cases, exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system of a targeted user. The Cisco WebEx Players are applications that are used to play back WebEx meeting recordings that have been recorded on the computer of an on-line meeting attendee. The players can be automatically installed when the user accesses a recording file that is hosted on a WebEx server. The player can also be manually installed for offline playback after downloading the application from www.webex.com . If the WebEx recording player was automatically installed, it will
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://securitytracker.com/id?1025015http://tools.cisco.com/security/center/viewAlert.x?alertId=22016http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6913f.shtmlhttp://www.coresecurity.com/content/webex-atp-and-wrf-overflow-vulnerabilitieshttp://www.securityfocus.com/archive/1/516095/100/0/threadedhttp://www.securityfocus.com/bid/46075http://www.vupen.com/english/advisories/2011/0261https://exchange.xforce.ibmcloud.com/vulnerabilities/65076http://securitytracker.com/id?1025015http://tools.cisco.com/security/center/viewAlert.x?alertId=22016http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6913f.shtmlhttp://www.coresecurity.com/content/webex-atp-and-wrf-overflow-vulnerabilitieshttp://www.securityfocus.com/archive/1/516095/100/0/threadedhttp://www.securityfocus.com/bid/46075http://www.vupen.com/english/advisories/2011/0261https://exchange.xforce.ibmcloud.com/vulnerabilities/65076
2011-02-02
Published