10

CVE-2005-2758

Integer signedness error in the administrative interface for Symantec AntiVirus Scan Engine 4.0 and 4.3 allows remote attackers to execute arbitrary code via crafted HTTP headers with negative values, which lead to a heap-based buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
SymantecAntivirus Scan Engine Version4.0 Editionbluecoat
SymantecAntivirus Scan Engine Version4.0 Editionclearswift
SymantecAntivirus Scan Engine Version4.0 Editionnetapp_filer
SymantecAntivirus Scan Engine Version4.0 Editionnetapp_netcache
SymantecAntivirus Scan Engine Version4.3 Editioncaching
SymantecAntivirus Scan Engine Version4.3 Editionclearswift
SymantecAntivirus Scan Engine Version4.3 Editionmicrosoft_sharepoint
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 22.57% 0.955
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C