9.3
CVE-2005-2618
- EPSS 49.61%
- Veröffentlicht 31.12.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename handled by kvarcve.dll, (3) a TAR archive with a long filename that is extracted to a directory with a long path handled by the TAR reader (tarrdr.dll), (4) an email that contains a long HTTP, FTP, or // link handled by the HTML speed reader (htmsr.dll) or (5) an email containing a crafted long link handled by the HTML speed reader (htmsr.dll).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Lotus Notes Version6.0.1
Ibm ≫ Lotus Notes Version6.0.2
Ibm ≫ Lotus Notes Version6.0.3
Ibm ≫ Lotus Notes Version6.0.4
Ibm ≫ Lotus Notes Version6.0.5
Ibm ≫ Lotus Notes Version6.5
Ibm ≫ Lotus Notes Version6.5.1
Ibm ≫ Lotus Notes Version6.5.2
Ibm ≫ Lotus Notes Version6.5.3
Ibm ≫ Lotus Notes Version6.5.4
Ibm ≫ Lotus Notes Version7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 49.61% | 0.975 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.