9.3

CVE-2006-3890

Exploit

Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execute arbitrary code via a long FilePattern attribute in a WZFILEVIEW object, a different vulnerability than CVE-2006-5198.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WinzipWinzip Version <= 10.0
WinzipWinzip Version7.0
WinzipWinzip Version8.0
WinzipWinzip Version8.1
WinzipWinzip Version8.1 Updatesr1
WinzipWinzip Version9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 49.56% 0.977
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C