Vulnerability Details CVE-2009-0538
Format string vulnerability in Symantec pcAnywhere before 12.5 SP1 allows local users to read and modify arbitrary memory locations, and cause a denial of service (application crash) or possibly have unspecified other impact, via format string specifiers in the pathname of a remote control file (aka .CHF file).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.3%
CVSS Severity
CVSS v2 Score 4.6
Products affected by CVE-2009-0538
-
cpe:2.3:a:symantec:pcanywhere:-
-
cpe:2.3:a:symantec:pcanywhere:10.0
-
cpe:2.3:a:symantec:pcanywhere:10.5
-
cpe:2.3:a:symantec:pcanywhere:11.0
-
cpe:2.3:a:symantec:pcanywhere:11.0.0.730
-
cpe:2.3:a:symantec:pcanywhere:11.0.1
-
cpe:2.3:a:symantec:pcanywhere:11.0.1.764
-
cpe:2.3:a:symantec:pcanywhere:11.5
-
cpe:2.3:a:symantec:pcanywhere:11.5.1
-
cpe:2.3:a:symantec:pcanywhere:12.0
-
cpe:2.3:a:symantec:pcanywhere:12.1
-
cpe:2.3:a:symantec:pcanywhere:12.1.0
-
cpe:2.3:a:symantec:pcanywhere:8.0
-
cpe:2.3:a:symantec:pcanywhere:8.0.1
-
cpe:2.3:a:symantec:pcanywhere:8.0.2
-
cpe:2.3:a:symantec:pcanywhere:9.0
-
cpe:2.3:a:symantec:pcanywhere:9.0.1
-
cpe:2.3:a:symantec:pcanywhere:9.2