CVE-2012-0708 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 31.4% (pctl 98)
Patch early
A public exploit exists.
Description
Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 31.38% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-04-22 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ibm | rational clearquest |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IBM Rational ClearQuest CQOle - Remote Code Execution (Metasploit) | 2012-07-05 |
References
- http://osvdb.org/81443
- http://secunia.com/advisories/48933
- http://www.ibm.com/support/docview.wss?uid=swg21591705
- http://www.securityfocus.com/bid/53170
- http://www.securitytracker.com/id?1026958
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73492
- http://osvdb.org/81443
- http://secunia.com/advisories/48933
- http://www.ibm.com/support/docview.wss?uid=swg21591705
- http://www.securityfocus.com/bid/53170
- http://www.securitytracker.com/id?1026958
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73492
→ the Explorer · watch your stack · NVD