9.3

CVE-2007-1498

Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy Orchestrator (ePO) before 3.6.1 Patch 1 and ProtectionPilot (PRP) before 1.5.0 HotFix allow remote attackers to execute arbitrary code via a long argument to the (1) ExportSiteList and (2) VerifyPackageCatalog functions, and (3) unspecified vectors involving a swprintf function call.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Epolicy Orchestrator Version 3.5.0
Mcafee ≫ Epolicy Orchestrator Version 3.6.0
Mcafee ≫ Epolicy Orchestrator Version 3.6.1
Mcafee ≫ Protectionpilot Version 1.1.1 Update p3
Mcafee ≫ Protectionpilot Version 1.5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.73% 0.939
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052960.html
Patch
http://secunia.com/advisories/24466
Patch
Vendor Advisory
http://securityreason.com/securityalert/2444
http://www.kb.cert.org/vuls/id/714593
US Government Resource
http://www.securityfocus.com/bid/22952
Patch
http://www.securitytracker.com/id?1017757
http://www.vupen.com/english/advisories/2007/0931
https://knowledge.mcafee.com/article/25/612495_f.SAL_Public.html
Patch
https://knowledge.mcafee.com/article/26/612496_f.SAL_Public.html
Patch