← back
CVE-2012-0708

CVE-2012-0708

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 31%
from disclosure to weapon74 days
Published on NVDApr 22
1st PoC+74d
metasploit+27d
exploitation probability
31%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 before 7.1.1.9, 7.1.2 before 7.1.2.6, and 8.0.0 before 8.0.0.2 allows remote attackers to execute arbitrary code via a crafted web page that leverages a RegisterSchemaRepoFromFileByDbSet function-prototype mismatch.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.