9.3

CVE-2008-5539

RISING Antivirus 21.06.31.00 and possibly 20.61.42.00, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rising-global ≫ Rising Antivirus Version 20.61.42.00
   Microsoft ≫ Internet Explorer Version 6
   Microsoft ≫ Internet Explorer Version 7
Rising-global ≫ Rising Antivirus Version 21.06.31.00
   Microsoft ≫ Internet Explorer Version 6
   Microsoft ≫ Internet Explorer Version 7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.26% 0.951
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://securityreason.com/securityalert/4723
http://www.securityfocus.com/archive/1/498995/100/0/threaded
http://www.securityfocus.com/archive/1/499043/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/47435