Back to search
CVE-2011-10015
Published: Aug 13, 2025
Modified: May 25, 2026
PUBLISHED
Description
Cytel Studio version 9.0 and earlier is vulnerable to a stack-based buffer overflow triggered by parsing a malformed .CY3 file. The vulnerability occurs when the application copies user-controlled strings into a fixed-size stack buffer (256 bytes) without proper bounds checking. Exploitation allows arbitrary code execution when the crafted file is opened.
| Vendor | Product | Versions |
|---|---|---|
Cytel Inc. | Cytel Studio | affected 0 - <= 9.0 |
Weaknesses (CWE)
References
http://aluigi.altervista.org/adv/cytel_1-adv.txt
technical-description
exploit
https://www.vulncheck.com/advisories/cytel-studio-cy3-file-stack-buffer-overflow
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now