4.4

CVE-2006-7037

Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the password field with a hash of a known password, (2) modify timestamps to avoid detection of modifications, (3) remove locks by removing the "is-locked" attribute, and (4) view locked data, which is stored in plaintext.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mathsoft ≫ Mathcad Version 12
   Microsoft ≫ Windows 2000
   Microsoft ≫ Windows 2003 Server Version sp2
   Microsoft ≫ Windows 95
   Microsoft ≫ Windows 98 Update gold
   Microsoft ≫ Windows 98se
   Microsoft ≫ Windows Me
   Microsoft ≫ Windows Nt Version 4.0
   Microsoft ≫ Windows Xp Update gold
Mathsoft ≫ Mathcad Version 13
   Microsoft ≫ Windows 2000
   Microsoft ≫ Windows 2003 Server Version sp2
   Microsoft ≫ Windows 95
   Microsoft ≫ Windows 98 Update gold
   Microsoft ≫ Windows 98se
   Microsoft ≫ Windows Me
   Microsoft ≫ Windows Nt Version 4.0
   Microsoft ≫ Windows Xp Update gold
Mathsoft ≫ Mathcad Version 13.1
   Microsoft ≫ Windows 2000
   Microsoft ≫ Windows 2003 Server Version sp2
   Microsoft ≫ Windows 95
   Microsoft ≫ Windows 98 Update gold
   Microsoft ≫ Windows 98se
   Microsoft ≫ Windows Me
   Microsoft ≫ Windows Nt Version 4.0
   Microsoft ≫ Windows Xp Update gold
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.232
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://securityreason.com/securityalert/2305
http://www.securityfocus.com/archive/1/436441/30/4560/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/27115
https://exchange.xforce.ibmcloud.com/vulnerabilities/27116
https://exchange.xforce.ibmcloud.com/vulnerabilities/27117
https://exchange.xforce.ibmcloud.com/vulnerabilities/27118