Lucene search

K
cveMitreCVE-2005-2996
HistorySep 20, 2005 - 10:03 p.m.

CVE-2005-2996

2005-09-2022:03:00
mitre
web.nvd.nist.gov
27
cve-2005-2996
buffer overflow
veritas storage exec
storagecentral
dcom server
nvd
security vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

High

EPSS

0.023

Percentile

89.8%

Multiple heap-based and stack-based buffer overflows in certain DCOM server components in VERITAS Storage Exec Storage Exec 5.3 before Hotfix 9 and StorageCentral 5.2 before Hot Fix 2 allow remote attackers to execute arbitrary code via certain ActiveX controls.

Affected configurations

Nvd
Node
symantec_veritasstorage_execMatch5.3_rev._2190r
OR
symantec_veritasstoragecentralMatch5.2_rev._2190r
VendorProductVersionCPE
symantec_veritasstorage_exec5.3_rev._2190rcpe:2.3:a:symantec_veritas:storage_exec:5.3_rev._2190r:*:*:*:*:*:*:*
symantec_veritasstoragecentral5.2_rev._2190rcpe:2.3:a:symantec_veritas:storagecentral:5.2_rev._2190r:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

High

EPSS

0.023

Percentile

89.8%