peter bassill · operator
$ cve CVE-2011-5002 JSON

CVE-2011-5002 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 7.5% (pctl 94)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in Final Draft 8 before 8.02 allow remote attackers to execute arbitrary code via a .fdx or .fdxt file with long (1) Word, (2) Transition, (3) Location, (4) Extension, (5) SceneIntro, (6) TimeOfDay, and (7) Character elements.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS7.51% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2011-12-25
Last modified2026-06-16

Affected (1)

VendorProduct
finaldraftfinaldraft

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD