Showing 3 vulnerabilities on this page for Arm Whois

Signals CISA KEV Ransomware Nuclei
Armcode vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Arm Whois 3.11 Buffer Overflow via ASLR Bypass

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft a malicious input file with a 672-byte offset to overwrite the nSEH and SEH pointers, enabling code execution through exception handler hijacking.

CWE-120Jun 1, 2026
CVSS8.6v4.0EPSS0.162%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Arm Whois 3.11 Buffer Overflow via SEH Overwrite

Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized input to the IP address or domain field. Attackers can craft malicious input exceeding 658 bytes with shellcode to overwrite the structured exception handler and gain command execution when the application processes the input.

CWE-121Jun 1, 2026
CVSS9.3v4.0EPSS0.923%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Arm Whois 3.11 Denial of Service via Buffer Overflow

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a malicious buffer of 700 bytes into the IP address or domain input field to trigger a denial of service condition.

CWE-120May 30, 2026
CVSS6.9v4.0EPSS0.14%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX