CVE-2014-2135
published 2014-05-08CVE-2014-2135: Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.79%
88.7th percentile
Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .arf file, aka Bug IDs CSCul87216 and CSCuj07603.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_advanced_recording_format_player | — | — |
| cisco | webex_advanced_recording_format_player | — | — |
| cisco | webex_advanced_recording_format_player | — | — |
| cisco | webex_recording_format_and_advanced_recording_format_players | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
| cisco | webex_recording_format_player | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco9.3CRITICAL
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wr8q-6g9v-2p34: Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28
ghsa_unreviewed·2022-05-17
CVE-2014-2135 [HIGH] CWE-119 GHSA-wr8q-6g9v-2p34: Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28
Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .arf file, aka Bug IDs CSCul87216 and CSCuj07603.
Red Hat
kernel: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page()
vendor_redhat·2024-03-04·CVSS 5.5
CVE-2021-47090 [MEDIUM] CWE-20 kernel: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page()
kernel: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page()
In the Linux kernel, the following vulnerability has been resolved:
mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page()
Hulk Robot reported a panic in put_page_testzero() when testing
madvise() with MADV_SOFT_OFFLINE. The BUG() is triggered when retrying
get_any_page(). This is because we keep MF_COUNT_INCREASED flag in
second try but the refcnt is not increased.
page dumped because: VM_BUG_ON_PAGE(page_ref_count(page) == 0)
------------[ cut here ]------------
kernel BUG at include/linux/mm.h:737!
invalid opcode: 0000 [#1] PREEMPT SMP
CPU: 5 PID: 2135 Comm: sshd Tainted: G B 5.16.0-rc6-dirty #373
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014
RIP: releas
Cisco
Multiple Vulnerabilities in the Cisco WebEx Recording Format and Advanced Recording Format Players
vendor_cisco·2014-05-07·CVSS 9.3
CVE-2014-2132 [CRITICAL] CWE-20 Multiple Vulnerabilities in the Cisco WebEx Recording Format and Advanced Recording Format Players
Multiple Vulnerabilities in the Cisco WebEx Recording Format and Advanced Recording Format Players
Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players. Exploitation of these vulnerabilities could allow a remote attacker to cause an affected player to crash and, in some cases, could allow a remote attacker to execute arbitrary code on the system of a targeted user.
The Cisco WebEx Players are applications that are used to play back WebEx meeting recordings that have been recorded on the computer of an online meeting attendee. The players can be automatically installed when the user accesses a recording file that is hosted on a WebEx server.
Cisco has updated affected versions of the Cisco WebEx Business Suit
Cisco
Multiple Vulnerabilities in the Cisco WebEx Recording Format and Advanced Recording Format Players
vendor_cisco
CVE-2014-2135 Multiple Vulnerabilities in the Cisco WebEx Recording Format and Advanced Recording Format Players
CVE-2014-2135: Multiple Vulnerabilities in the Cisco WebEx Recording Format and Advanced Recording Format Players
Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players. Exploitation of these vulnerabilities could allow a remote attacker to cause an affected player to crash and, in some cases, could allow a remote attacker to execute arbitrary code on the system of a targeted user. The Cisco WebEx Players are applications that are used to play back WebEx meeting recordings that have been recorded on the computer of an online meeting attendee. The players can be automatically installed when the user accesses a recording file that is hosted on a WebEx server. Cisco has updated affected versions of the Cisco WebEx B
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-05-08
Published