{"api_version":"1","generated_at":"2026-07-23T13:05:08+00:00","cve":"CVE-2019-12553","urls":{"html":"https://cve.report/CVE-2019-12553","api":"https://cve.report/api/cve/CVE-2019-12553.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-12553","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-12553"},"summary":{"title":"CVE-2019-12553","description":"In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the StrCat function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-06-05 17:29:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-787"],"metrics":[],"references":[{"url":"https://www.sweetscape.com/010editor/release_notes.html","name":"https://www.sweetscape.com/010editor/release_notes.html","refsource":"CONFIRM","tags":["Release Notes","Vendor Advisory"],"title":"010 Editor - Release Notes","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/ereisr00/bagofbugz/blob/master/010Editor/strcat_heap_overflow.bt","name":"https://github.com/ereisr00/bagofbugz/blob/master/010Editor/strcat_heap_overflow.bt","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"bagofbugz/strcat_heap_overflow.bt at master · ereisr00/bagofbugz · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-12553","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-12553","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"12553","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sweetscape","cpe5":"010_editor","cpe6":"9.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"12553","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sweetscape","cpe5":"010_editor","cpe6":"9.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-12553","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the StrCat function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://www.sweetscape.com/010editor/release_notes.html","url":"https://www.sweetscape.com/010editor/release_notes.html"},{"refsource":"MISC","name":"https://github.com/ereisr00/bagofbugz/blob/master/010Editor/strcat_heap_overflow.bt","url":"https://github.com/ereisr00/bagofbugz/blob/master/010Editor/strcat_heap_overflow.bt"}]}},"nvd":{"publishedDate":"2019-06-05 17:29:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-787"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sweetscape:010_editor:9.0.1:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"12553","Ordinal":"150892","Title":"CVE-2019-12553","CVE":"CVE-2019-12553","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"12553","Ordinal":"1","NoteData":"In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the StrCat function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"12553","Ordinal":"2","NoteData":"2019-06-05","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"12553","Ordinal":"3","NoteData":"2019-06-05","Type":"Other","Title":"Modified"}]}}}