CVE-2019-12553
Summary
| CVE | CVE-2019-12553 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-05 17:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the StrCat function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sweetscape | 010 Editor | 9.0.1 | All | All | All |
| Application | Sweetscape | 010 Editor | 9.0.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 010 Editor - Release Notes | CONFIRM | www.sweetscape.com | Release Notes, Vendor Advisory |
| bagofbugz/strcat_heap_overflow.bt at master · ereisr00/bagofbugz · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.