CVE-2019-12551
Summary
| CVE | CVE-2019-12551 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-22 20:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sweetscape | 010 Editor | 9.0.1 | All | All | All |
| Application | Sweetscape | 010 Editor | 9.0.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ereisr00 | MISC | ereisr00.github.io | Exploit, Third Party Advisory |
| bagofbugz/010Editor at master · ereisr00/bagofbugz · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| 010 Editor Manual - Release Notes | MISC | www.sweetscape.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.