10

CVE-2005-0441

Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or "sa" role privileges to execute arbitrary code via (5) a crafted install java statement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SybaseAdaptive Server Enterprise Version11.03.3 Editionlinux
SybaseAdaptive Server Enterprise Version11.5 Editiondigital_unix
SybaseAdaptive Server Enterprise Version11.5 Editionhp
SybaseAdaptive Server Enterprise Version11.5 Editionsun
SybaseAdaptive Server Enterprise Version11.5 Editionwin
SybaseAdaptive Server Enterprise Version11.5.1 Editiondigital_unix
SybaseAdaptive Server Enterprise Version11.5.1 Editionhp
SybaseAdaptive Server Enterprise Version11.5.1 Editionsun
SybaseAdaptive Server Enterprise Version11.5.1 Editionwin
SybaseAdaptive Server Enterprise Version11.9.2 Editiondigital_unix
SybaseAdaptive Server Enterprise Version11.9.2 Editionhp
SybaseAdaptive Server Enterprise Version11.9.2 Editionsun
SybaseAdaptive Server Enterprise Version11.9.2 Editionwin
SybaseAdaptive Server Enterprise Version12.0 Editiondigital_unix
SybaseAdaptive Server Enterprise Version12.0 Editionhp
SybaseAdaptive Server Enterprise Version12.0 Editionsun
SybaseAdaptive Server Enterprise Version12.0 Editionwin
SybaseAdaptive Server Enterprise Version12.0.1 Editiondigital_unix
SybaseAdaptive Server Enterprise Version12.0.1 Editionhp
SybaseAdaptive Server Enterprise Version12.0.1 Editionsun
SybaseAdaptive Server Enterprise Version12.0.1 Editionwin
SybaseAdaptive Server Enterprise Version12.5 Editiondigital_unix
SybaseAdaptive Server Enterprise Version12.5 Editionhp
SybaseAdaptive Server Enterprise Version12.5 Editionlinux
SybaseAdaptive Server Enterprise Version12.5 Editionsgi
SybaseAdaptive Server Enterprise Version12.5 Editionsun
SybaseAdaptive Server Enterprise Version12.5 Editionwin
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.55% 0.944
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2004-12/0315.html
Patch
Vendor Advisory
http://marc.info/?l=bugtraq&m=111272918117194&w=2
http://secunia.com/advisories/13632
Patch
Vendor Advisory
http://www.ngssoftware.com/advisories/sybase-ase.txt
Vendor Advisory
http://www.securityfocus.com/archive/1/393851
Patch
Vendor Advisory
http://www.securityfocus.com/bid/12080
Patch
Vendor Advisory
http://www.sybase.com/detail/1%2C6904%2C1033894%2C00.html
http://www.sybase.com/detail?id=1034520
Patch
Vendor Advisory
http://www.sybase.com/detail?id=1034752
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/19354
https://exchange.xforce.ibmcloud.com/vulnerabilities/19974
https://exchange.xforce.ibmcloud.com/vulnerabilities/19976
https://exchange.xforce.ibmcloud.com/vulnerabilities/19978
https://exchange.xforce.ibmcloud.com/vulnerabilities/19979
https://exchange.xforce.ibmcloud.com/vulnerabilities/19980