Stack-Based Buffer Overflow in IBM Lotus Quickr ActiveX Control
CVE-2012-2176
Currently unrated
Summary
IBM Lotus Quickr has a vulnerability due to multiple stack-based buffer overflows in an ActiveX control included in qp2.cab. This affects versions prior to 8.2.0.27-002a for Domino. By sending a lengthy argument to the methods Attachment_Times or Import_Times, remote attackers could leverage this flaw to execute arbitrary code, compromising system integrity and security.
References
EPSS Score
60% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved