Lucene search

K
cve[email protected]CVE-2006-6201
HistoryDec 01, 2006 - 1:28 a.m.

CVE-2006-6201

2006-12-0101:28:00
web.nvd.nist.gov
25
cve-2006-6201
buffer overflow
borland
idsql32.dll
remote code execution
nvd
security vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.8 High

AI Score

Confidence

Low

0.157 Low

EPSS

Percentile

96.0%

Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function.

Affected configurations

NVD
Node
borland_softwarec\+\+_builderMatch5.x
OR
borland_softwarec\+\+_builderMatch6.x
OR
borland_softwarec\+\+_builderMatch2006
OR
borland_softwarec_builderMatch2006
OR
borland_softwaredelphiMatch5.x
OR
borland_softwaredelphiMatch6.x
OR
borland_softwaredelphiMatch7.x
OR
borland_softwaredelphiMatch2006
OR
borland_softwaredeveloper_studioMatch2006
OR
borland_softwareidsql32.dllMatch5.1.0.2
OR
borland_softwareidsql32.dllMatch5.1.0.4
OR
revillocmailserver

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.8 High

AI Score

Confidence

Low

0.157 Low

EPSS

Percentile

96.0%

Related for CVE-2006-6201