{"api_version":"1","generated_at":"2026-07-23T01:32:15+00:00","cve":"CVE-2012-0192","urls":{"html":"https://cve.report/CVE-2012-0192","api":"https://cve.report/api/cve/CVE-2012-0192.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-0192","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-0192"},"summary":{"title":"CVE-2012-0192","description":"Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.","state":"PUBLISHED","assigner":"ibm","published_at":"2012-01-23 15:55:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-189","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/47245","name":"http://secunia.com/advisories/47245","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA47245 - IBM Lotus Symphony Image Processing Integer Overflow Vulnerability - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21578684","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21578684","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72424","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72424","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/78345","name":"http://osvdb.org/78345","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/51591","name":"http://www.securityfocus.com/bid/51591","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Lotus Symphony Image Object Integer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-0192","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-0192","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"192","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_symphony","cpe6":"1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"192","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_symphony","cpe6":"3.0.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"192","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_symphony","cpe6":"3.0.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"192","vulnerable":"1","versionEndIncluding":"3.0.0.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_symphony","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T18:16:19.381Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"51591","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/51591"},{"name":"47245","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/47245"},{"name":"78345","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/78345"},{"name":"lotus-symphony-vclmi-bo(72424)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72424"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21578684"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-01-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"name":"51591","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/51591"},{"name":"47245","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/47245"},{"name":"78345","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/78345"},{"name":"lotus-symphony-vclmi-bo(72424)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72424"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21578684"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2012-0192","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"51591","refsource":"BID","url":"http://www.securityfocus.com/bid/51591"},{"name":"47245","refsource":"SECUNIA","url":"http://secunia.com/advisories/47245"},{"name":"78345","refsource":"OSVDB","url":"http://osvdb.org/78345"},{"name":"lotus-symphony-vclmi-bo(72424)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72424"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21578684","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21578684"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2012-0192","datePublished":"2012-01-23T15:00:00.000Z","dateReserved":"2011-12-14T00:00:00.000Z","dateUpdated":"2024-08-06T18:16:19.381Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-01-23 15:55:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-189","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_symphony:*:*:*:*:*:*:*:*","versionEndIncluding":"3.0.0.3","matchCriteriaId":"07FC4E0D-02AD-473D-8086-9613095D5209"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_symphony:1.3:*:*:*:*:*:*:*","matchCriteriaId":"F12C267E-7032-4C81-BF4B-55FDBC443A31"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_symphony:3.0.0.1:*:*:*:*:*:*:*","matchCriteriaId":"8A74E155-75B4-40E2-B3EE-4C0121159650"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_symphony:3.0.0.2:*:*:*:*:*:*:*","matchCriteriaId":"8BE246EA-BC50-42BB-B630-836D84FE9CFA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"192","Ordinal":"1","Title":"CVE-2012-0192","CVE":"CVE-2012-0192","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"192","Ordinal":"1","NoteData":"Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.","Type":"Description","Title":"CVE-2012-0192"},{"CveYear":"2012","CveId":"192","Ordinal":"2","NoteData":"2012-01-23","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"192","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}