Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 01:35
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/81443 - | |
References | () http://secunia.com/advisories/48933 - | |
References | () http://www.ibm.com/support/docview.wss?uid=swg21591705 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/53170 - | |
References | () http://www.securitytracker.com/id?1026958 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/73492 - |
Information
Published : 2012-04-22 18:55
Updated : 2025-04-11 00:51
NVD link : CVE-2012-0708
Mitre link : CVE-2012-0708
CVE.ORG link : CVE-2012-0708
JSON object : View
Products Affected
ibm
- rational_clearquest
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer