Lucene search

K
cve[email protected]CVE-2006-3985
HistoryAug 05, 2006 - 12:04 a.m.

CVE-2006-3985

2006-08-0500:04:00
CWE-119
web.nvd.nist.gov
25
cve-2006-3985
stack-based buffer overflow
dzips32.dll
conexware powerarchiver
zip archive
arbitrary code execution
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

75.2%

Stack-based buffer overflow in DZIPS32.DLL 6.0.0.4 in ConeXware PowerArchiver 9.62.03 allows user-assisted attackers to execute arbitrary code by adding a new file to a crafted ZIP archive that already contains a file with a long name.

Affected configurations

NVD
Node
conexwarepowerarchiverRange9.62.03
OR
conexwarepowerarchiverMatch8.10
OR
conexwarepowerarchiverMatch8.60
OR
conexwarepowerarchiverMatch9.5_beta_4
OR
conexwarepowerarchiverMatch9.5_beta_5
OR
conexwarepowerarchiverMatch9.25

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

75.2%

Related for CVE-2006-3985