« Volver al listado

CVE-2017-2155

Estado: ModificadaAlta (8.8)—

Desbordamiento de buffer en Hoozin Viewer versiones 2, 3, 4.1.5.15 y anteriores, 5.1.2.13 y anteriores y 6.0.3.09 y anteriores, que permitiría a atacantes remotos ejecutar código arbitrario a través de páginas web especialmente manipuladas.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-2155",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "ICON CORPORATION",
          "product": "Hoozin Viewer",
          "versions": [
            {
              "status": "affected",
              "version": "Ver2"
            }
          ]
        },
        {
          "vendor": "ICON CORPORATION",
          "product": "Hoozin Viewer",
          "versions": [
            {
              "status": "affected",
              "version": "Ver3"
            }
          ]
        },
        {
          "vendor": "ICON CORPORATION",
          "product": "Hoozin Viewer",
          "versions": [
            {
              "status": "affected",
              "version": "Ver4.1.5.15 and earlier"
            }
          ]
        },
        {
          "vendor": "ICON CORPORATION",
          "product": "Hoozin Viewer",
          "versions": [
            {
              "status": "affected",
              "version": "Ver5.1.2.13 and earlier"
            }
          ]
        },
        {
          "vendor": "ICON CORPORATION",
          "product": "Hoozin Viewer",
          "versions": [
            {
              "status": "affected",
              "version": "Ver6.0.3.09 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-04-28T16:59:02.120",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN93931029/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www.icon-co.jp/news/20170420/index.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN93931029/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.icon-co.jp/news/20170420/index.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in Hoozin Viewer 2, 3, 4.1.5.15 and earlier, 5.1.2.13 and earlier, and 6.0.3.09 and earlier allows remote attackers to execute arbitrary code via specially crafted webpage."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de buffer en Hoozin Viewer versiones 2, 3, 4.1.5.15 y anteriores, 5.1.2.13 y anteriores y 6.0.3.09 y anteriores, que permitiría a atacantes remotos ejecutar código arbitrario a través de páginas web especialmente manipuladas."
    }
  ],
  "lastModified": "2026-06-17T01:15:39.307",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:i.con_corporation:hoozin_viewer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A3A7338-338A-4C08-AA06-1663A0CD7C5C",
              "versionEndIncluding": "4.1.5.15"
            },
            {
              "criteria": "cpe:2.3:a:i.con_corporation:hoozin_viewer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F4C02F0-21D4-46D7-A6B9-35CE6680D0D9",
              "versionEndIncluding": "5.1.2.13"
            },
            {
              "criteria": "cpe:2.3:a:i.con_corporation:hoozin_viewer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D78A722-71AF-4992-A6A0-9CB70A6056B7",
              "versionEndIncluding": "6.0.3.09"
            },
            {
              "criteria": "cpe:2.3:a:i.con_corporation:hoozin_viewer:2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9DD8A38-CA5F-447A-8A7D-1B759F82AF47"
            },
            {
              "criteria": "cpe:2.3:a:i.con_corporation:hoozin_viewer:3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "629988EA-58D0-447E-9816-ECE49D121CCA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}