4.9

CVE-2007-3815

Buffer overflow in pirs32.exe in Poslovni informator Republike Slovenije (PIRS) 2007 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long search string in certain fields in the GUI.  NOTE: this may cross privilege boundaries if PIRS is used by data-entry workers who do not have full access to the underlying Windows environment.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Republike Slovenije ≫ Pirs Version 2007
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.357
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064627.html
Patch
http://osvdb.org/38697
http://securityreason.com/securityalert/2898
http://www.pirs.si/slo/index.php?dep_id=29&help_id=60
https://exchange.xforce.ibmcloud.com/vulnerabilities/35388