9.3
CVE-2008-1724
- EPSS 35.13%
- Veröffentlicht 11.04.2008 19:05:00
- Zuletzt bearbeitet 16.06.2026 22:52:22
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Stack-based buffer overflow in the IActiveXTransfer.FileTransfer method in the SecureTransport FileTransfer ActiveX control in vcst_en.dll 1.0.0.5 in Tumbleweed SecureTransport Server before 4.6.1 Hotfix 20 allows remote attackers to execute arbitrary code via a long remoteFile parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tumbleweed ≫ Securetransport Server App Version <= 4.6.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 35.13% | 0.982 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://secunia.com/advisories/29717
http://securityreason.com/securityalert/3806
http://www.aushack.com/200708-tumbleweed.txt
http://www.securityfocus.com/archive/1/490536/100/0/threaded
http://www.securityfocus.com/bid/28662
http://www.vupen.com/english/advisories/2008/1165/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/41692
https://www.exploit-db.com/exploits/5398