Lucene search

K
cveMitreCVE-2006-6676
HistoryDec 21, 2006 - 1:28 a.m.

CVE-2006-6676

2006-12-2101:28:00
CWE-189
mitre
web.nvd.nist.gov
22
cve-2006-6676
integer overflow
ole2 parser
chm parser
eset nod32 antivirus
remote code execution
buffer overflow

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.102

Percentile

95.0%

Integer overflow in the (a) OLE2 and (b) CHM parsers for ESET NOD32 Antivirus before 1.1743 allows remote attackers to execute arbitrary code via a crafted (1) .DOC or (2) .CAB file that triggers a heap-based buffer overflow.

Affected configurations

Nvd
Node
eset_softwarenod32_antivirusRange1.1742
OR
eset_softwarenod32_antivirusMatch1.0.11
OR
eset_softwarenod32_antivirusMatch1.0.12
OR
eset_softwarenod32_antivirusMatch1.0.13
VendorProductVersionCPE
eset_softwarenod32_antivirus*cpe:2.3:a:eset_software:nod32_antivirus:*:*:*:*:*:*:*:*
eset_softwarenod32_antivirus1.0.11cpe:2.3:a:eset_software:nod32_antivirus:1.0.11:*:*:*:*:*:*:*
eset_softwarenod32_antivirus1.0.12cpe:2.3:a:eset_software:nod32_antivirus:1.0.12:*:*:*:*:*:*:*
eset_softwarenod32_antivirus1.0.13cpe:2.3:a:eset_software:nod32_antivirus:1.0.13:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.102

Percentile

95.0%

Related for CVE-2006-6676