CVE-2013-3986
IBM Lotus Sametime - Memory Corruption
Title source: ruleDescription
IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote attackers to cause a denial of service (WebPlayer Firefox extension crash) via a crafted Audio Visual (AV) session.
Exploits (1)
metasploit
WORKING POC
by Chris John Riley, kicks4kittens · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/misc/ibm_sametime_webplayer_dos.rb
Scores
EPSS
0.3922
EPSS Percentile
97.3%
Details
CWE
CWE-119
Status
published
Products (2)
ibm/lotus_sametime
8.5.2
ibm/lotus_sametime
8.5.2.1
Published
Nov 08, 2013
Tracked Since
Feb 18, 2026