CVE-2012-6277

HIGHCVSS 7.8/10EPSS 7.92%

Last modified

CVE-2012-6277 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code.". EPSS estimates a 7.92% chance of exploitation in the next 30 days.

Description

Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code."

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
7.92%

94.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
IbmDomino>= 8.5.0, <= 8.5.3.6
IbmNotes>= 8.5, <= 8.5.3
SymantecData Loss Prevention Endpoint>= 11.0, < 11.6.1
SymantecData Loss Prevention Enforce\/Detection Servers>= 11.0, < 11.6.1
SymantecMail Security<= 6.5.7
SymantecMail Security<= 8.1.0
SymantecMail Security6.5.7
SymantecMessaging Gateway>= 9.5, < 10.0.1
HpAutonomy Keyview Idol< 10.16

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-6277?
Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code."
How severe is CVE-2012-6277?
CVE-2012-6277 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 7.92% probability of exploitation in the next 30 days.
How do I fix CVE-2012-6277?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-6277?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST