CVE-2012-2429: Xarrow

High severity, CVSS 10.0. EPSS: 3.8% chance of exploitation in the next 30 days.

The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecified vectors.

Affected products

  • Xarrow Xarrow: up to and including 3.4

Published 2012-05-25. Last modified 2026-06-16.