CVE-2013-5559 : Detail

CVE-2013-5559

Overflow
44.76%V3
Network
2013-11-04
14h00 +00:00
2013-11-11
09h00 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document, aka Bug ID CSCuj58139.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Metrics

Metrics Score Severity CVSS Vector Source
V2 6.8 AV:N/AC:M/Au:N/C:P/I:P/A:P [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Products Mentioned

Configuraton 0

Cisco>>Anyconnect_secure_mobility_client >> Version 2.0

Cisco>>Anyconnect_secure_mobility_client >> Version 2.1

Cisco>>Anyconnect_secure_mobility_client >> Version 2.2

Cisco>>Anyconnect_secure_mobility_client >> Version 2.2.128

Cisco>>Anyconnect_secure_mobility_client >> Version 2.2.133

Cisco>>Anyconnect_secure_mobility_client >> Version 2.2.136

Cisco>>Anyconnect_secure_mobility_client >> Version 2.2.140

Cisco>>Anyconnect_secure_mobility_client >> Version 2.3

Cisco>>Anyconnect_secure_mobility_client >> Version 2.3.185

Cisco>>Anyconnect_secure_mobility_client >> Version 2.3.254

Cisco>>Anyconnect_secure_mobility_client >> Version 2.3.2016

Cisco>>Anyconnect_secure_mobility_client >> Version 2.4

Cisco>>Anyconnect_secure_mobility_client >> Version 2.4

Cisco>>Anyconnect_secure_mobility_client >> Version 2.4.0202

Cisco>>Anyconnect_secure_mobility_client >> Version 2.4.1012

Cisco>>Anyconnect_secure_mobility_client >> Version 2.4.4004

Cisco>>Anyconnect_secure_mobility_client >> Version 2.4.4014

Cisco>>Anyconnect_secure_mobility_client >> Version 2.4.5004

Cisco>>Anyconnect_secure_mobility_client >> Version 2.4.7030

Cisco>>Anyconnect_secure_mobility_client >> Version 2.4.7073

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.0217

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.1025

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.2001

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.2006

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.2010

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.2011

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.2014

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.2017

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.2018

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.2019

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.3041

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.3046

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.3051

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.3054

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.3055

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.5112

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.5116

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.5118

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.5125

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.5130

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.5131

Cisco>>Anyconnect_secure_mobility_client >> Version 2.5.6005

References