CVE-2015-2052
published 2015-02-23CVE-2015-2052: Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary code…
PriorityP276critical10CVSS 2.0
AVNACLAuNCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
5.21%
91.5th percentile
Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary code via a long string in a GetDeviceSettings action to the HNAP interface.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-645_firmware | <= 1.04b12 | — |
| harfbuzz_project | harfbuzz | >= 0 < 0.9.27-1ubuntu1.1 | 0.9.27-1ubuntu1.1 |
| harfbuzz_project | harfbuzz | >= 0 < 1.0.1-1ubuntu0.1 | 1.0.1-1ubuntu0.1 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv7.6HIGH
vulncheck10.0CRITICAL
vendor_redhat7.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cpxr-x8w8-p34j: Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev
ghsa_unreviewed·2022-05-17
CVE-2015-2052 [HIGH] CWE-119 GHSA-cpxr-x8w8-p34j: Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev
Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary code via a long string in a GetDeviceSettings action to the HNAP interface.
OSV
harfbuzz vulnerabilities
osv·2016-08-24·CVSS 7.6
CVE-2015-8947 harfbuzz vulnerabilities
harfbuzz vulnerabilities
Kostya Serebryany discovered that HarfBuzz incorrectly handled memory. A
remote attacker could use this issue to cause HarfBuzz to crash, resulting
in a denial of service, or possibly execute arbitrary code. (CVE-2015-8947)
It was discovered that HarfBuzz incorrectly handled certain length checks.
A remote attacker could use this issue to cause HarfBuzz to crash,
resulting in a denial of service, or possibly execute arbitrary code.
This issue only applied to Ubuntu 16.04 LTS. (CVE-2016-2052)
VulnCheck
D-Link DIR-645 Router Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2015·CVSS 10.0
CVE-2015-2052 [CRITICAL] D-Link DIR-645 Router Improper Restriction of Operations within the Bounds of a Memory Buffer
D-Link DIR-645 Router Improper Restriction of Operations within the Bounds of a Memory Buffer
Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary code via a long string in a GetDeviceSettings action to the HNAP interface.
Affected: D-Link DIR-645 Router
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://blog.newskysecurity.com/masuta-satori-creators-second-botnet-weaponizes-a-new-router-exploit-2ddc51cc52a7
Red Hat
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
vendor_redhat·2016-01-24·CVSS 7.6
CVE-2016-2052 [HIGH] chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.
Package: harfbuzz (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
vendor_redhat·2016-01-24·CVSS 7.6
CVE-2015-8947 [HIGH] chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.
Package: harfbuzz (Red Hat Enterprise Linux 7) - Will not fix
No detection rules found.
No public exploits indexed.
2015-02-23
Published
Exploited in the wild