CVE-2014-2994: Buffer Overflow
Published Apr 27, 2014
·Updated
Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to execute arbitrary code via an HTML file containing an IMG element with a long URL (src attribute).
Affected Software
1 affected component
Acunetix Web Vulnerability Scanner=8-build_20120704
Event History
Apr 27, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·04:32 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2994?
CVE-2014-2994 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2014-2994?
To fix CVE-2014-2994, upgrade to a version of Acunetix Web Vulnerability Scanner that is not affected by this vulnerability.
3
Who is affected by CVE-2014-2994?
CVE-2014-2994 affects users of Acunetix Web Vulnerability Scanner version 8 build 20120704.
4
What is the nature of the vulnerability in CVE-2014-2994?
CVE-2014-2994 is a stack-based buffer overflow caused by improperly handling long URLs in HTML IMG elements.
5
Can CVE-2014-2994 be exploited remotely?
Yes, CVE-2014-2994 can be exploited remotely by attackers through specially crafted HTML files.