6.8

CVE-2006-3961

Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf.

Data is provided by the National Vulnerability Database (NVD)
McafeeAntispyware Version2005
McafeeAntispyware Version2006
McafeePersonal Firewall Plus Version2004
McafeePersonal Firewall Plus Version2005
McafeePersonal Firewall Plus Version2006
McafeePrivacy Service Version2004
McafeePrivacy Service Version2005
McafeePrivacy Service Version2006
McafeeQuickclean Version2004
McafeeQuickclean Version2005
McafeeQuickclean Version2006
McafeeSecurity Center Version4.3
McafeeSecurity Center Version6.0
McafeeSecurity Center Version6.0.22
McafeeSecurity Center Version6.0.23
McafeeSpamkiller Version5.0
McafeeSpamkiller Version6.0
McafeeSpamkiller Version7.0
McafeeVirusscan Version2004
McafeeVirusscan Version2005
McafeeVirusscan Version2006
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 70.79% 0.985
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.