cbcvebase.
CVE-2012-3480
published 2012-08-25

CVE-2012-3480: Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka…

PriorityP425medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EXPLOIT
EPSS
0.99%
59.0th percentile
Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianglibc< glibc 2.13-36 (bookworm)glibc 2.13-36 (bookworm)
gnuglibc
gnuglibc>= 0 < 2.13-362.13-36
gnuglibc>= 0 < 2.13-362.13-36
gnuglibc>= 0 < 2.13-362.13-36
gnuglibc>= 0 < 2.13-362.13-36
vmwarevcenter_server
vmwarevmware_esxi
vmwarevsphere

CVSS provenance

nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.