CVE-2011-10015

Severity CVSS v4.0:
CRITICAL
Type:
CWE-121 Stack-based Buffer Overflow
Publication date:
13/08/2025
Last modified:
14/08/2025

Description

Cytel Studio version 9.0 and earlier is vulnerable to a stack-based buffer overflow triggered by parsing a malformed .CY3 file. The vulnerability occurs when the application copies user-controlled strings into a fixed-size stack buffer (256 bytes) without proper bounds checking. Exploitation allows arbitrary code execution when the crafted file is opened.