7.5

CVE-2004-0193

Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6, allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Iss ≫ Blackice Agent Server Version 3.6eca
Iss ≫ Blackice Pc Protection Version 3.6cbd
Iss ≫ Blackice Server Protection Version 3.6cbz
Iss ≫ Realsecure Desktop Version 3.6eca
Iss ≫ Realsecure Desktop Version 3.6ecf
Iss ≫ Realsecure Desktop Version 7.0ebg
Iss ≫ Realsecure Desktop Version 7.0epk
Iss ≫ Realsecure Guard Version 3.6ecb
Iss ≫ Realsecure Network Version 7.0 Update xpu_20.15
Iss ≫ Realsecure Sentry Version 3.6ecf
Iss ≫ Realsecure Server Sensor Version 7.0 Update xpu20.16
Iss ≫ Proventia A Series Xpu Version 20.15
Iss ≫ Proventia G Series Xpu Version 22.3
Iss ≫ Proventia M Series Xpu Version 1.30
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8% 0.94
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=107789851117176&w=2
http://secunia.com/advisories/10988
http://www.eeye.com/html/Research/Advisories/AD20040226.html
http://www.eeye.com/html/Research/Upcoming/20040213.html
Vendor Advisory
http://www.kb.cert.org/vuls/id/150326
Patch
Third Party Advisory
US Government Resource
http://www.osvdb.org/4072
http://www.securityfocus.com/bid/9752
http://xforce.iss.net/xforce/alerts/id/165
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/15207