10
CVE-2007-5580
- EPSS 6.43%
- Veröffentlicht 15.12.2007 01:46:00
- Zuletzt bearbeitet 16.06.2026 22:46:26
- Erkennungen
Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0.225, 5.1 before 5.1.0.106, and 5.2 before 5.2.0.238 on Windows allows remote attackers to execute arbitrary code via a crafted SMB packet in a TCP session on port (1) 139 or (2) 445.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Security Agent Version 2.1
Cisco ≫ Security Agent Version 3
Cisco ≫ Security Agent Version 4.0
Cisco ≫ Security Agent Version 4.0.1
Cisco ≫ Security Agent Version 4.0.2
Cisco ≫ Security Agent Version 4.0.3
Cisco ≫ Security Agent Version 4.0.3.728
Cisco ≫ Security Agent Version 4.5
Cisco ≫ Security Agent Version 4.5.1
Cisco ≫ Security Agent Version 4.5.1.639
Cisco ≫ Security Agent Version 4.5.1.657
Cisco ≫ Security Agent Version 4.5.1.659
Cisco ≫ Security Agent Version 5.0
Cisco ≫ Security Agent Version 5.0.0.201
Cisco ≫ Security Agent Version 5.0.193
Cisco ≫ Security Agent Version 5.1
Cisco ≫ Security Agent Version 5.1.79
Cisco ≫ Security Agent Version 5.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.43% | 0.928 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://osvdb.org/39521
http://secunia.com/advisories/27947
http://securityreason.com/securityalert/3425
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsl00618
http://www.cisco.com/en/US/products/products_security_advisory09186a008090a434.shtml
http://www.nsfocus.com/english/homepage/research/0702.htm
http://www.securityfocus.com/archive/1/484669/100/100/threaded
http://www.securityfocus.com/bid/26723
http://www.securitytracker.com/id?1019046
http://www.vupen.com/english/advisories/2007/4103