10

CVE-2006-6627

Integer overflow in the packed PE file parsing implementation in BitDefender products before 20060829, including Antivirus, Antivirus Plus, Internet Security, Mail Protection for Enterprises, and Online Scanner; and BitDefender products for Microsoft ISA Server and Exchange 5.5 through 2003; allows remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow, aka the "cevakrnl.xmd vulnerability."

Data is provided by the National Vulnerability Database (NVD)
SoftwinBitdefender Versionisa_server
SoftwinBitdefender Versionms_exchange_5.5
SoftwinBitdefender Versionms_exchange_2000
SoftwinBitdefender Versionms_exchange_2003
SoftwinBitdefender Antivirus Versionplus
SoftwinBitdefender Mail Protection Versionenterprises
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 9.86% 0.927
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C