Description
Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.
Published: 2012-01-23
Score: 9.3 Critical
EPSS: 8.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Ibm Lotus Symphony
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-08-06T18:16:19.381Z

Reserved: 2011-12-14T00:00:00.000Z

Link: CVE-2012-0192

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-01-23T15:55:00.943

Modified: 2026-04-29T01:13:23.040

Link: CVE-2012-0192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses