7.5

CVE-2006-0474

Multiple integer overflows in Shareaza 2.2.1.0 allow remote attackers to execute arbitrary code via (1) a large packet length field, which causes an overflow in the ReadBuffer function in (a) BTPacket.cpp and (b) EDPacket.cpp, or (2) a large packet, which causes a heap-based overflow in the Write function in (c) Packet.h.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ShareazaShareaza Version2.2.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.92% 0.89
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0887.html
http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/BTPacket.cpp?r1=1.5&r2=1.5.4.1
http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/EDPacket.cpp?r1=1.15&r2=1.15.2.1
http://securityreason.com/securityalert/382
http://www.hustlelabs.com/shareaza_advisory.pdf
Vendor Advisory
http://www.securityfocus.com/archive/1/423293/100/0/threaded
http://www.securityfocus.com/bid/16399
https://exchange.xforce.ibmcloud.com/vulnerabilities/24342
https://exchange.xforce.ibmcloud.com/vulnerabilities/24343
https://exchange.xforce.ibmcloud.com/vulnerabilities/24344