Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2013-1116

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cisco WebEx Advanced Recording Format(ARF)Player是美国思科(Cisco)公司的一款播放器,它主要用于播放ARF格式的WebEx录制文件。 Cisco WebEx ARF Player中存在堆内存损坏漏洞,该漏洞源于软件没有正确处理.arf文件。远程未授权的攻击者可借助特制的.arf文件利用该漏洞执行任意代码或造成受影响应用程序崩溃,导致拒绝服务。以下版本受到影响:27.11.26,27.21.10,27.25.10,27.32.1,27.32.10,28.4

AI Predicted 9.8 Difficulty: Easy EPSS 3.12% · P87
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2013-1116

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Buffer overflow in Cisco WebEx Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted ARF file, aka Bug IDs CSCue74147 and CSCub28383.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Cisco WebEx ARF Player 堆内存损坏漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco WebEx Advanced Recording Format(ARF)Player是美国思科(Cisco)公司的一款播放器,它主要用于播放ARF格式的WebEx录制文件。 Cisco WebEx ARF Player中存在堆内存损坏漏洞,该漏洞源于软件没有正确处理.arf文件。远程未授权的攻击者可借助特制的.arf文件利用该漏洞执行任意代码或造成受影响应用程序崩溃,导致拒绝服务。以下版本受到影响:27.11.26,27.21.10,27.25.10,27.32.1,27.32.10,28.4
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2013-1116

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-1116

登录查看更多情报信息。

Vendor Advisories for CVE-2013-1116 (1)

Same Patch Batch · n/a · 2013-09-06 · 17 CVEs total

CVE-2012-5990 Cisco Prime Network Control Systems和Wireless Control System 跨站脚本漏洞
CVE-2013-1115 Cisco WebEx ARF Player 远程内存损坏漏洞
CVE-2013-1117 Cisco WebEx WRF Player Exception Handler 远程缓冲区溢出漏洞
CVE-2013-1118 Cisco WebEx WRF Player 栈缓冲区溢出漏洞
CVE-2013-1119 Cisco WebEx WRF Player JPEG DHT Index 远程内存损坏漏洞
CVE-2013-1228 Cisco Jabber for Windows 证书验证安全绕过漏洞
CVE-2013-3599 Trivantis CourseMill Learning Management System 安全绕过漏洞
CVE-2013-3600 Trivantis CourseMill Learning Management System 安全绕过漏洞
CVE-2013-3601 Trivantis CourseMill Learning Management System 安全绕过漏洞
CVE-2013-3602 Trivantis CourseMill Learning Management System ‘admindocumentworker.jsp’SQL注入漏洞
CVE-2013-3603 Trivantis CourseMill Learning Management System 跨站脚本漏洞
CVE-2013-3604 Trivantis CourseMill Learning Management System 多个跨站脚本漏洞
CVE-2013-3605 Trivantis CourseMill Learning Management System 跨站请求伪造漏洞
CVE-2013-5706 Trivantis Coursemill Learning Management System 多个跨站脚本漏洞
CVE-2013-5707 Trivantis Coursemill Learning Management System 多个跨站脚本漏洞
CVE-2013-5708 Trivantis Coursemill Learning Management System 跨站请求伪造漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2013-1116

No comments yet


Leave a comment