peter bassill · operator
$ cve CVE-2012-0708 JSON

CVE-2012-0708 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 31.4% (pctl 98)

Patch early

A public exploit exists.

Description

Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS31.38% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2012-04-22
Last modified2026-06-16

Affected (1)

VendorProduct
ibmrational clearquest

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD