10
CVE-2005-2758
- EPSS 22.57%
- Published 05.10.2005 19:02:00
- Last modified 03.04.2025 01:03:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Integer signedness error in the administrative interface for Symantec AntiVirus Scan Engine 4.0 and 4.3 allows remote attackers to execute arbitrary code via crafted HTTP headers with negative values, which lead to a heap-based buffer overflow.
Data is provided by the National Vulnerability Database (NVD)
Symantec ≫ Antivirus Scan Engine Version4.0
Symantec ≫ Antivirus Scan Engine Version4.0 Editionbluecoat
Symantec ≫ Antivirus Scan Engine Version4.0 Editionclearswift
Symantec ≫ Antivirus Scan Engine Version4.0 Editionnetapp_filer
Symantec ≫ Antivirus Scan Engine Version4.0 Editionnetapp_netcache
Symantec ≫ Antivirus Scan Engine Version4.3
Symantec ≫ Antivirus Scan Engine Version4.3 Editioncaching
Symantec ≫ Antivirus Scan Engine Version4.3 Editionclearswift
Symantec ≫ Antivirus Scan Engine Version4.3 Editionmicrosoft_sharepoint
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 22.57% | 0.955 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|