CVE-2011-4874 | Date: (C)2012-04-13 (M)2023-12-22 |
Use-after-free vulnerability in MICROSYS PROMOTIC before 8.1.7 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (data corruption and application crash) via a crafted project (aka .pra) file.
CVSS Score and Metrics +CVSS Score and Metrics -CVSS V2 Severity: |
CVSS Score : 7.9 |
Exploit Score: 5.5 |
Impact Score: 10.0 |
|
CVSS V2 Metrics: |
Access Vector: ADJACENT_NETWORK |
Access Complexity: MEDIUM |
Authentication: NONE |
Confidentiality: COMPLETE |
Integrity: COMPLETE |
Availability: COMPLETE |
| |