Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft a malicious input file with a 672-byte offset to overwrite the nSEH and SEH pointers, enabling code execution through exception handler hijacking.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 01 Jun 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Armcode
Armcode arm Whois |
|
| Vendors & Products |
Armcode
Armcode arm Whois |
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft a malicious input file with a 672-byte offset to overwrite the nSEH and SEH pointers, enabling code execution through exception handler hijacking. | |
| Title | Arm Whois 3.11 Buffer Overflow via ASLR Bypass | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-01T21:00:22.371Z
Reserved: 2026-06-01T11:50:04.770Z
Link: CVE-2018-25432
No data.
Status : Received
Published: 2026-06-01T22:16:16.583
Modified: 2026-06-01T22:16:16.583
Link: CVE-2018-25432
No data.
OpenCVE Enrichment
Updated: 2026-06-01T22:30:03Z
Weaknesses