[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-8572Date: (C)2015-12-21   (M)2023-12-22


Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lines in a PCX file, or (4) DataSubBlock or (5) GlobalColorTable in a GIF file.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://www.zerodayinitiative.com/advisories/ZDI-15-615
http://www.zerodayinitiative.com/advisories/ZDI-15-616
http://www.zerodayinitiative.com/advisories/ZDI-15-618
http://www.zerodayinitiative.com/advisories/ZDI-15-619
http://www.zerodayinitiative.com/advisories/ZDI-15-620
https://knowledge.autodesk.com/support/design-review/downloads/caas/downloads/content/autodesk-design-review-2013-hotfix.html

CPE    1
cpe:/a:autodesk:design_review:2013
CWE    1
CWE-119

© SecPod Technologies