CVE-2012-6277
Last modified
CVE-2012-6277 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code.". EPSS estimates a 7.92% chance of exploitation in the next 30 days.
Description
Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code."
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Domino | >= 8.5.0, <= 8.5.3.6 |
| Ibm | Notes | >= 8.5, <= 8.5.3 |
| Symantec | Data Loss Prevention Endpoint | >= 11.0, < 11.6.1 |
| Symantec | Data Loss Prevention Enforce\/Detection Servers | >= 11.0, < 11.6.1 |
| Symantec | Mail Security | <= 6.5.7 |
| Symantec | Mail Security | <= 8.1.0 |
| Symantec | Mail Security | 6.5.7 |
| Symantec | Messaging Gateway | >= 9.5, < 10.0.1 |
| Hp | Autonomy Keyview Idol | < 10.16 |
References
- https://support.symantec.com/us/en/article.symsa1262.htmlVendor Advisory
- https://tools.cisco.com/security/center/viewAlert.x?alertId=27482Third Party Advisory
- https://vulmon.com/vulnerabilitydetails?qid=CVE-2012-6277Third Party Advisory
- https://www.energy.gov/cio/articles/v-118-ibm-lotus-domino-multiple-vulnerabilitiesThird Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/849841/Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/56610Third Party Advisory, VDB Entry
- https://www.tenable.com/plugins/nessus/67192Third Party Advisory
- https://support.symantec.com/us/en/article.symsa1262.htmlVendor Advisory
- https://tools.cisco.com/security/center/viewAlert.x?alertId=27482Third Party Advisory
- https://vulmon.com/vulnerabilitydetails?qid=CVE-2012-6277Third Party Advisory
- https://www.energy.gov/cio/articles/v-118-ibm-lotus-domino-multiple-vulnerabilitiesThird Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/849841/Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/56610Third Party Advisory, VDB Entry
- https://www.tenable.com/plugins/nessus/67192Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-6277?
How severe is CVE-2012-6277?
How do I fix CVE-2012-6277?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-6271Adobe Shockwave Player through 11.6.8.638 allows remote atta…
- CVE-2012-6272Multiple cross-site scripting (XSS) vulnerabilities in Dell …
- CVE-2012-6273SQL injection vulnerability in BigAntSoft BigAnt IM Message …
- CVE-2012-6274BigAntSoft BigAnt IM Message Server does not require authent…
- CVE-2012-6275Multiple stack-based buffer overflows in AntDS.exe in BigAnt…
- CVE-2012-6276Directory traversal vulnerability in the web-based managemen…
- CVE-2012-6278Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2012-6279Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2012-6280Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2012-6281Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2012-6282Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2012-6283Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2012-6277?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
