CVE-2012-3797

critical

Description

Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, does not properly check packet sizes before reusing packet memory buffers, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a short crafted packet with a certain opcode.

References

https://www.hmisource.com/otasuke/news/2012/0606.html

https://www.hmisource.com/otasuke/download/update/server_ex/server_ex/Readme_E.txt

http://www.securityfocus.com/bid/53499

http://secunia.com/advisories/49172

http://ics-cert.us-cert.gov/advisories/ICSA-12-179-01

http://aluigi.org/adv/proservrex_1-adv.txt

Details

Source: Mitre, NVD

Published: 2012-06-25

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.12499