5

CVE-2006-3840

The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is not properly handled by the SMB_Mailslot_Heap_Overflow decode.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IssBlackice Pc Protection Version3.6cpk
IssBlackice Server Protection Version3.6cpk
IssProventia Desktop Version8.0.675.1790
IssProventia Desktop Version8.0.812.1790
IssRealsecure Desktop Version7.0epk
IssRealsecure Network Version7.0
IssRealsecure Server Sensor Version7.0
IssProventia Server Version1.0.914.1880
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.12% 0.882
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P