Lucene search

K
cve[email protected]CVE-2006-6627
HistoryDec 18, 2006 - 11:28 a.m.

CVE-2006-6627

2006-12-1811:28:00
web.nvd.nist.gov
19
cve-2006-6627
bitdefender
integer overflow
pe file parsing
remote code execution
vulnerability

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.3 High

AI Score

Confidence

High

0.152 Low

EPSS

Percentile

95.9%

Integer overflow in the packed PE file parsing implementation in BitDefender products before 20060829, including Antivirus, Antivirus Plus, Internet Security, Mail Protection for Enterprises, and Online Scanner; and BitDefender products for Microsoft ISA Server and Exchange 5.5 through 2003; allows remote attackers to execute arbitrary code via a crafted file, which triggers a heap-based buffer overflow, aka the “cevakrnl.xmd vulnerability.”

Affected configurations

NVD
Node
softwinbitdefenderMatchisa_server
OR
softwinbitdefenderMatchms_exchange_5.5
OR
softwinbitdefenderMatchms_exchange_2000
OR
softwinbitdefenderMatchms_exchange_2003
OR
softwinbitdefender_antivirus
OR
softwinbitdefender_antivirusMatchplus
OR
softwinbitdefender_internet_security
OR
softwinbitdefender_mail_protectionMatchenterprises
OR
softwinbitdefender_online_scanner

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.3 High

AI Score

Confidence

High

0.152 Low

EPSS

Percentile

95.9%

Related for CVE-2006-6627