CVE-2012-10057

CVSS V2 None CVSS V3 None
Description
Lattice Semiconductor ispVM System v18.0.2 contains a buffer overflow vulnerability in its handling of .xcf project files. When parsing the version attribute of the ispXCF XML tag, the application fails to properly validate input length, allowing a specially crafted file to overwrite memory on the stack. This can result in arbitrary code execution under the context of the user who opens the file. The vulnerability is triggered locally by opening a malicious .xcf file and does not require elevated privileges.
Overview
  • CVE ID
  • CVE-2012-10057
  • Assigner
  • VulnCheck
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2025-08-13T20:35:07.498Z
  • Last Modified Date
  • 2025-08-13T20:35:07.498Z
History
Created Old Value New Value Data Type Notes
2025-08-14 10:01:34 Added to TrackCVE