← Vulnerability feed

Vulnerability record · CVE-2018-5262 · published 12 January 2018

CVE-2018-5262: Flexense diskboss out-of-bounds write vulnerability

Flexense · Diskboss

A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged account.

9.8 CVSS 3.0 Critical EPSS 39% · top 1.5% CWE-787 · Out-of-bounds write
9.8CVSS 3.0 base score, v2 10.0
39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged account.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-5262 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2020-36882Flexense diskboss unrestricted file upload vulnerabilityFlexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial o…EPSS 0.62%8.6CVE-2020-36881Flexense diskboss memory buffer overflow vulnerabilityFlexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Input Directory' component that allows unauthenticated attackers to …EPSS 0.37%8.6CVE-2020-36880Flexense diskboss memory buffer overflow vulnerabilityFlexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Reports and Data Directory' field that allows an attacker to execute…EPSS 0.24%8.1CVE-2018-5261Flexense diskboss missing encryption vulnerabilityAn issue was discovered in Flexense DiskBoss 8.8.16 and earlier. Due to the usage of plaintext information from the handshake as input for the encryp…EPSS 0.46%7.8CVE-2017-7310Flexense disk tools XML import buffer overflow allows code executionA buffer overflow in the Import Command of multiple Flexense products (SyncBreeze, DiskSorter, DiskBoss, DiskPulse, DiskSavvy, DupScout, VX Search) b…EPSS 54%analysed7.5CVE-2017-15665Flexense diskboss vulnerabilityIn Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GE…EPSS 9.1%6.1CVE-2018-10294Flexense diskboss cross-site scripting vulnerabilityFlexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS.EPSS 0.69%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed

Source: NIST National Vulnerability Database (record CVE-2018-5262), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.