CVE-2010-3269
Summary
| CVE | CVE-2010-3269 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-02-02 23:00:31 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to use of a function pointer in a callback mechanism. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Webex Advanced Recording Format Player | 26.49 | All | All | All |
| Application | Cisco | Webex Advanced Recording Format Player | 27.10 | All | All | All |
| Application | Cisco | Webex Advanced Recording Format Player | 27.11.0.3328 | All | All | All |
| Application | Cisco | Webex Advanced Recording Format Player | 27.12 | All | All | All |
| Application | Cisco | Webex Advanced Recording Format Player | 27.13 | All | All | All |
| Application | Cisco | Webex Recording Format Player | 26.49 | All | All | All |
| Application | Cisco | Webex Recording Format Player | 27.10 | All | All | All |
| Application | Cisco | Webex Recording Format Player | 27.11.0.3328 | All | All | All |
| Application | Cisco | Webex Recording Format Player | 27.12 | All | All | All |
| Application | Cisco | Webex Recording Format Player | 27.13 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco WebEx WRF and ARF File Format Multiple Remote Buffer Overflow Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| tools.cisco.com/security/center/viewAlert.x | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Patch |
| Cisco Security Advisory: Multiple Cisco WebEx Player Vulnerabilities - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| Core Security Technologies | af854a3a-2127-422b-91ae-364da2661108 | www.coresecurity.com | Patch |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Cisco WebEx Player and WebEx Meeting Center Stack Overflows Let Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.