Lucene search

K
cve[email protected]CVE-2007-2514
HistoryJun 06, 2007 - 10:30 a.m.

CVE-2007-2514

2007-06-0610:30:00
web.nvd.nist.gov
23
cve-2007-2514
stack-based buffer overflow
xferwan.exe
remote code execution
symantec discovery
numara asset manager
centennial uk ltd discovery

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

Low

0.827 High

EPSS

Percentile

98.5%

Stack-based buffer overflow in XferWan.exe as used in multiple products including (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0, and (3) Centennial UK Ltd Discovery 2006 Feature Pack, allows remote attackers to execute arbitrary code via a long request. NOTE: this might be a reservation duplicate of CVE-2007-1173.

Affected configurations

NVD
Node
centennialdiscoveryMatch2006_featurepack1
OR
numaraasset_managerMatch8.0
OR
symantecdiscoveryMatch6.5

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

Low

0.827 High

EPSS

Percentile

98.5%