CVE-2016-4359
9.8
CRITICAL · CVSS 3.0 · EPSS 15.8% (pctl 97)
Patch early
EPSS 15.8% — above the 10% action threshold.
Description
Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allows remote attackers to execute arbitrary code via a long -server_name value, aka ZDI-CAN-3516.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 15.77% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-06-08 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| hp | loadrunner |
| hp | performance center |
References
- http://www.securityfocus.com/bid/90975
- http://www.securitytracker.com/id/1036006
- http://www.zerodayinitiative.com/advisories/ZDI-16-363
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05157423
- https://www.tenable.com/security/research/tra-2016-16
- http://www.securityfocus.com/bid/90975
- http://www.securitytracker.com/id/1036006
- http://www.zerodayinitiative.com/advisories/ZDI-16-363
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05157423
- https://www.tenable.com/security/research/tra-2016-16
→ the Explorer · watch your stack · NVD