CVE-2012-0708
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 31%
from disclosure to weapon74 days
Published on NVDApr 22
1st PoC+74d
metasploit+27d
exploitation probability
31%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/19576unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.