CVE-2013-1119
published 2013-09-06CVE-2013-1119: Buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.12%
86.3th percentile
Buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DHT index value in JPEG data within a WRF file, aka Bug ID CSCuc24503.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_recording_format_and_advanced_recording_format_players | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in the Cisco WebEx Recording Format and Advanced Recording Format Players
vendor_cisco·2013-09-04·CVSS 9.3
CVE-2013-1115 [CRITICAL] CWE-119 Multiple Vulnerabilities in the Cisco WebEx Recording Format and Advanced Recording Format Players
Multiple Vulnerabilities in the Cisco WebEx Recording Format and Advanced Recording Format Players
Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players. Exploitation of these vulnerabilities could allow a remote attacker to crash an affected player, and in some cases, could allow a remote attacker to execute arbitrary code on the system of a targeted user.
The Cisco WebEx Players are applications that are used to play back WebEx meeting recordings that have been recorded on the computer of an on-line meeting attendee. The players can be automatically installed when the user accesses a recording file that is hosted on a WebEx server.
Cisco has updated affected versions of the Cisco WebEx Business Suite meetin
Cisco
Multiple Vulnerabilities in the Cisco WebEx Recording Format and Advanced Recording Format Players
vendor_cisco
CVE-2013-1119 Multiple Vulnerabilities in the Cisco WebEx Recording Format and Advanced Recording Format Players
CVE-2013-1119: Multiple Vulnerabilities in the Cisco WebEx Recording Format and Advanced Recording Format Players
Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players. Exploitation of these vulnerabilities could allow a remote attacker to crash an affected player, and in some cases, could allow a remote attacker to execute arbitrary code on the system of a targeted user. The Cisco WebEx Players are applications that are used to play back WebEx meeting recordings that have been recorded on the computer of an on-line meeting attendee. The players can be automatically installed when the user accesses a recording file that is hosted on a WebEx server. Cisco has updated affected versions of the Cisco WebEx Business
GHSA
GHSA-8whc-72gh-79xc: Buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28
ghsa_unreviewed·2022-05-17
CVE-2013-1119 [HIGH] CWE-119 GHSA-8whc-72gh-79xc: Buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28
Buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DHT index value in JPEG data within a WRF file, aka Bug ID CSCuc24503.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-09-06
Published