7.2

CVE-2009-0681

PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) cause a denial of service (crash) and execute arbitrary code via a crafted IRP in an IOCTL request to pgpwded.sys.

Data is provided by the National Vulnerability Database (NVD)
PgpDesktop Update- Editionhome Version <= 9.9.0
PgpDesktop Update- Editionpro Version <= 9.9.0
PgpDesktop Version8.0 Editionhome
PgpDesktop Version8.0 Editionpro
PgpDesktop Version9.0 Editionhome
PgpDesktop Version9.0 Editionprofessional
PgpDesktop Version9.0.6 Update- Editionhome
PgpDesktop Version9.0.6 Update- Editionpro
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.12
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.