5.4
CVE-2005-3887
- EPSS 1.89%
- Veröffentlicht 29.11.2005 21:03:00
- Zuletzt bearbeitet 16.06.2026 22:17:49
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Gadu-Gadu 7.20 does not properly handle MS-DOS device names in filenames, which allows remote attackers to (1) cause a denial of service (hang) via an image filename of AUX: sent twice (hang), or (2) write to the LPT1 port via a filename of "LPT1:".
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gadu-gadu ≫ Gadu-gadu Instant Messenger Version7.20
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.89% | 0.768 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 4.9 | 6.9 |
AV:N/AC:H/Au:N/C:N/I:N/A:C
|
http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0658.html
http://marc.info/?l=bugtraq&m=113261573023912&w=2
http://secunia.com/advisories/17597/
http://www.osvdb.org/21015
http://www.securityfocus.com/bid/15520/
https://exchange.xforce.ibmcloud.com/vulnerabilities/23148