peter bassill · operator
$ cve CVE-2016-4359 JSON

CVE-2016-4359

9.8
CRITICAL · CVSS 3.0 · EPSS 15.8% (pctl 97)

Patch early

EPSS 15.8% — above the 10% action threshold.

Description

Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allows remote attackers to execute arbitrary code via a long -server_name value, aka ZDI-CAN-3516.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS15.77% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2016-06-08
Last modified2026-06-17

Affected (2)

VendorProduct
hploadrunner
hpperformance center

References

→ the Explorer  ·  watch your stack  ·  NVD