RSS   Vulnerabilities for 'Xarrow'   RSS

2012-05-25
 
CVE-2012-2429

CWE-189
 

 
The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecified vectors.

 
 
CVE-2012-2428

CWE-189
 

 
Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers an out-of-bounds read operation.

 
 
CVE-2012-2427

CWE-119
 

 
Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger an invalid free operation.

 
 
CVE-2012-2426

CWE-399
 

 
The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors.

 


Copyright 2024, cxsecurity.com

 

Back to Top