7.2
CVE-2007-4648
- EPSS 0.92%
- Veröffentlicht 31.08.2007 23:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:30
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The nvcoaft51 driver in Norman Virus Control (NVC) 5.82 uses weak permissions (unrestricted write access) for the NvcOa device, which allows local users to gain privileges by (1) triggering a buffer overflow in a kernel pool via a string argument to ioctl 0xBF67201C; or by (2) sending a crafted KEVENT structure through ioctl 0xBF672028 to overwrite arbitrary memory locations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Norman ≫ Norman Virus Control Version5.82
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.92% | 0.557 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://securityreason.com/securityalert/3087
http://www.48bits.com/exploits/nvc.rar
http://www.securityfocus.com/archive/1/478224/100/0/threaded
http://www.securityfocus.com/bid/25499
http://www.securitytracker.com/id?1018636
https://exchange.xforce.ibmcloud.com/vulnerabilities/36373