9.3

CVE-2008-4564

Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file.

Data is provided by the National Vulnerability Database (NVD)
AutonomyKeyview Export Sdk Version <= 10.4
AutonomyKeyview Export Sdk Version2.0
AutonomyKeyview Export Sdk Version9.2.0
AutonomyKeyview Export Sdk Version10.3
AutonomyKeyview Filter Sdk Version <= 10.4
AutonomyKeyview Filter Sdk Version2.0
AutonomyKeyview Filter Sdk Version9.2.0
AutonomyKeyview Filter Sdk Version10.3
AutonomyKeyview Viewer Sdk Version <= 10.4
AutonomyKeyview Viewer Sdk Version2.0
AutonomyKeyview Viewer Sdk Version9.2.0
AutonomyKeyview Viewer Sdk Version10.3
IbmLotus Notes Version5.0.3
IbmLotus Notes Version5.0.12
IbmLotus Notes Version6.0
IbmLotus Notes Version6.0.1
IbmLotus Notes Version6.0.2
IbmLotus Notes Version6.0.3
IbmLotus Notes Version6.0.4
IbmLotus Notes Version6.0.5
IbmLotus Notes Version6.5
IbmLotus Notes Version6.5.1
IbmLotus Notes Version6.5.2
IbmLotus Notes Version6.5.3
IbmLotus Notes Version6.5.4
IbmLotus Notes Version6.5.5
IbmLotus Notes Version6.5.5 Editionfp2
IbmLotus Notes Version6.5.5 Editionfp3
IbmLotus Notes Version6.5.6
IbmLotus Notes Version6.5.6 Editionfp2
IbmLotus Notes Version7.0
IbmLotus Notes Version7.0.1
IbmLotus Notes Version7.0.2
IbmLotus Notes Version7.0.2 Editionfp1
IbmLotus Notes Version7.0.3
IbmLotus Notes Version8.0
SymantecBrightmail Version5.0 Editionappliance
SymantecData Loss Prevention Detection Servers Version8.1 Editionlinux
SymantecData Loss Prevention Detection Servers Version8.1 Editionwindows
SymantecEnforce Version7.0
SymantecEnforce Version8.0
SymantecEnforce Version8.1 Editionlinux
SymantecEnforce Version8.1 Editionwindows
SymantecMail Security Version5.0 Editionappliance
SymantecMail Security Version5.0.0
SymantecMail Security Version5.0.0 Editionsmtp
SymantecMail Security Version5.0.0.24 Editionappliance
SymantecMail Security Version5.0.1 Editionsmtp
SymantecMail Security Version5.0.1.181 Editionsmtp
SymantecMail Security Version5.0.1.182 Editionsmtp
SymantecMail Security Version5.0.1.189 Editionsmtp
SymantecMail Security Version5.0.1.200 Editionsmtp
SymantecMail Security Version5.0.10 Editionmicrosoft_exchange
SymantecMail Security Version5.0.11 Editionmicrosoft_exchange
SymantecMail Security Version6.0.6 Updatemicrosoft_exchange
SymantecMail Security Version6.0.7 Updatemicrosoft_exchange
SymantecMail Security Version7.5..4.29 Editiondomino
SymantecMail Security Version7.5.3.25 Editiondomino
SymantecMail Security Version7.5.5.32 Editiondomino
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 56.29% 0.98
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.