CVE Database · CVE-2012-2427
CVSS v3.1
N/A
EPSS
3.97%
Published
May 25, 2012
Modified
Apr 28, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger an invalid free operation.
Weaknesses (CWE)
Affected Products (1)
References (2)