CVE-2012-2515: Buffer Overflow
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EMC Captiva Quickscan Pro 4.6 SP1; GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; GE Intelligent Platforms Proficy HMI/SCADA iFIX 5.0 and 5.1; GE Intelligent Platforms Proficy Pulse 1.0; GE Intelligent Platforms Proficy Batch Execution 5.6; GE Intelligent Platforms SI7 I/O Driver 7.20 through 7.42; and other products, allow remote attackers to execute arbitrary code via a long string in the second argument to the (1) JumpMappedID or (2) JumpURL method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2515?
CVE-2012-2515 is classified as a high severity vulnerability due to multiple stack-based buffer overflows.
How do I fix CVE-2012-2515?
To fix CVE-2012-2515, it is recommended to update the affected software to the latest version provided by the vendor.
Which software is affected by CVE-2012-2515?
CVE-2012-2515 affects EMC Documentum ApplicationXtender Desktop 5.4, EMC Captiva Quickscan Pro 4.6 SP1, and several versions of GE Intelligent Platforms Proficy Historian.
What type of vulnerability is CVE-2012-2515?
CVE-2012-2515 is a buffer overflow vulnerability that can lead to remote code execution.
Is CVE-2012-2515 being actively exploited?
As of now, there are no publicly available reports indicating active exploitation of CVE-2012-2515.