7.5
CVE-2005-4438
- EPSS 6.27%
- Veröffentlicht 21.12.2005 01:03:00
- Zuletzt bearbeitet 16.06.2026 22:18:47
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Heap-based buffer overflow in Dec2Rar.dll 3.2.14.3, as distributed in the Symantec Antivirus Library and used by various Symantec products, allows remote attackers to execute arbitrary code via RAR archives with sub-block headers that contain incorrect values in the length field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dec2rar.Dll ≫ Dec2rar.Dll Version3.2.14.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.27% | 0.927 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/18131
http://securityreason.com/securityalert/276
http://securitytracker.com/id?1015384
http://www.kb.cert.org/vuls/id/305272
http://www.rem0te.com/public/images/symc2.pdf
http://www.securityfocus.com/archive/1/419853/100/0/threaded
http://www.securityfocus.com/bid/15971
http://www.vupen.com/english/advisories/2005/3003