CVE-2012-3937
published 2012-10-25CVE-2012-3937: Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code…
PriorityP347critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.26%
91.6th percentile
Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCtz72967.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-86gj-xpxv-927w: Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28
ghsa_unreviewed·2022-05-17
CVE-2012-3937 [HIGH] CWE-119 GHSA-86gj-xpxv-927w: Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28
Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCtz72967.
Cisco
Multiple Vulnerabilities in the Cisco WebEx Recording Format Player
vendor_cisco·2012-10-10·CVSS 9.3
CVE-2012-3936 [CRITICAL] CWE-119 Multiple Vulnerabilities in the Cisco WebEx Recording Format Player
Multiple Vulnerabilities in the Cisco WebEx Recording Format Player
The Cisco WebEx Recording Format (WRF) player contains six buffer overflow vulnerabilities. In some cases, exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system with the privileges of a targeted user.
The Cisco WebEx WRF Player is an application used to play back WRF WebEx meeting recordings that have been recorded on a WebEx meeting site or on the computer of an online meeting attendee. The Cisco WebEx WRF Player can be automatically installed when the user accesses a recording file that is hosted on a WebEx meeting site. The Cisco WebEx WRF Player can also be manually installed for offline playback after downloading the application from http://www.webex.com/play-webex
Cisco
Multiple Vulnerabilities in the Cisco WebEx Recording Format Player
vendor_cisco
CVE-2012-3937 Multiple Vulnerabilities in the Cisco WebEx Recording Format Player
CVE-2012-3937: Multiple Vulnerabilities in the Cisco WebEx Recording Format Player
The Cisco WebEx Recording Format (WRF) player contains six buffer overflow vulnerabilities. In some cases, exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system with the privileges of a targeted user. The Cisco WebEx WRF Player is an application used to play back WRF WebEx meeting recordings that have been recorded on a WebEx meeting site or on the computer of an online meeting attendee. The Cisco WebEx WRF Player can be automatically installed when the user accesses a recording file that is hosted on a WebEx meeting site. The Cisco WebEx WRF Player can also be manually installed for offline playback after downloading the application from http://www.webex.c
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/86142http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121010-webexhttp://www.securityfocus.com/bid/55866http://www.securitytracker.com/id?1027639http://osvdb.org/86142http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121010-webexhttp://www.securityfocus.com/bid/55866http://www.securitytracker.com/id?1027639
2012-10-25
Published