CVE-2013-5447

IBM Forms Viewer <4.0.0.3, <8.0.1.1 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary code via an XFDL form with a long fontname value.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/30789
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/ibm_forms_viewer_fontname.rb

Scores

EPSS 0.6832
EPSS Percentile 98.6%

Details

CWE
CWE-119
Status published
Products (5)
ibm/forms_viewer 4.0.0
ibm/forms_viewer 4.0.0.1
ibm/forms_viewer 4.0.0.2
ibm/forms_viewer 8.0.0
ibm/forms_viewer 8.0.1
Published Dec 10, 2013
Tracked Since Feb 18, 2026