9.3

CVE-2009-3037

Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec Mail Security, Symantec BrightMail Appliance, Symantec Data Loss Prevention (DLP), and other products, allows remote attackers to execute arbitrary code via a crafted .xls spreadsheet attachment.

Data is provided by the National Vulnerability Database (NVD)
IbmLotus Notes Version5.0
IbmLotus Notes Version5.0.1
IbmLotus Notes Version5.0.2
IbmLotus Notes Version5.0.3
IbmLotus Notes Version5.0.4
IbmLotus Notes Version5.0.5
IbmLotus Notes Version5.0.6
IbmLotus Notes Version5.0.9a
IbmLotus Notes Version5.0.10
IbmLotus Notes Version5.0.11
IbmLotus Notes Version5.0.12
IbmLotus Notes Version5.02
IbmLotus Notes Version6.0
IbmLotus Notes Version6.0.1
IbmLotus Notes Version6.0.2
IbmLotus Notes Version6.0.3
IbmLotus Notes Version6.0.4
IbmLotus Notes Version6.0.5
IbmLotus Notes Version6.5
IbmLotus Notes Version6.5.1
IbmLotus Notes Version6.5.2
IbmLotus Notes Version6.5.3
IbmLotus Notes Version6.5.4
IbmLotus Notes Version6.5.5
IbmLotus Notes Version6.5.5 Editionfp2
IbmLotus Notes Version6.5.5 Editionfp3
IbmLotus Notes Version6.5.6
IbmLotus Notes Version6.5.6 Editionfp2
IbmLotus Notes Version7.0
IbmLotus Notes Version7.0.0
IbmLotus Notes Version7.0.1
IbmLotus Notes Version7.0.2
IbmLotus Notes Version7.0.2 Editionfp1
IbmLotus Notes Version7.0.3
IbmLotus Notes Version8.0
IbmLotus Notes Version8.0.0
IbmLotus Notes Version8.0.1
IbmLotus Notes Version8.5
SymantecBrightmail Appliance Version8.0.0
SymantecBrightmail Appliance Version8.0.1
SymantecData Loss Prevention Detection Servers Version8.1.1 Editionlinux
SymantecData Loss Prevention Detection Servers Version8.1.1 Editionwindows
SymantecData Loss Prevention Detection Servers Version9.0.1 Editionlinux
SymantecData Loss Prevention Detection Servers Version9.0.1 Editionwindows
SymantecMail Security Version5.0 Editionsmtp
SymantecMail Security Version5.0.0 Editionsmtp
SymantecMail Security Version5.0.1 Editionsmtp
SymantecMail Security Version5.0.1.181 Editionsmtp
SymantecMail Security Version5.0.1.182 Editionsmtp
SymantecMail Security Version5.0.1.189 Editionsmtp
SymantecMail Security Version5.0.1.200 Editionsmtp
SymantecMail Security Version5.0.10 Editionmicrosoft_exchange
SymantecMail Security Version5.0.11 Editionmicrosoft_exchange
SymantecMail Security Version5.0.12 Editionmicrosoft_exchange
SymantecMail Security Version6.0.6 Editionmicrosoft_exchange
SymantecMail Security Version6.0.7 Editionmicrosoft_exchange
SymantecMail Security Version6.0.8 Editionmicrosoft_exchange
SymantecMail Security Version7.5.3.25 Editiondomino
SymantecMail Security Version7.5.4.29 Editiondomino
SymantecMail Security Version7.5.5.32 Editiondomino
SymantecMail Security Version7.5.6 Editiondomino
SymantecMail Security Version8.0 Editiondomino
SymantecMail Security Appliance Version5.0.0.24
SymantecMail Security Appliance Version5.0.0.36
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 16.84% 0.944
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.