7.5
CVSSv2

CVE-2016-4359

Published: 08/06/2016 Updated: 03/11/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allows remote malicious users to execute arbitrary code via a long -server_name value, aka ZDI-CAN-3516.

Vulnerable Product Search on Vulmon Subscribe to Product

hp loadrunner 12.01

hp loadrunner 12.00

hp loadrunner 11.52

hp loadrunner 12.50

hp loadrunner 12.02

hp performance center 12.50

hp performance center 12.20

hp performance center 11.52

hp performance center 12.01

hp performance center 12.00