peter bassill · operator
$ cve CVE-2013-3928 JSON

CVE-2013-3928 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 37.3% (pctl 98)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS37.33% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2014-03-11
Last modified2026-06-16

Affected (1)

VendorProduct
jpchachachasys draw ies

Public exploits

SourceTitleDate
exploit-dbChasys Draw IES - Local Buffer Overflow (Metasploit)2013-08-15

References

→ the Explorer  ·  watch your stack  ·  NVD