Lucene search

K
cveFlexeraCVE-2007-5405
HistoryApr 10, 2008 - 6:05 p.m.

CVE-2007-5405

2008-04-1018:05:00
CWE-119
flexera
web.nvd.nist.gov
33
cve-2007-5405
buffer overflow
kpagrdr.dll
applix presents reader
autonomy
verity
keyview
ibm lotus notes
symantec mail security
activepdf docconverter
arbitrary code execution
encoding attribute

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.783

Percentile

98.3%

Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a .ag file with (1) a long ENCODING attribute in a *BEGIN tag, (2) a long token, or (3) the initial *BEGIN tag.

Affected configurations

Nvd
Node
activepdfdocconverterMatch3.8.2_.5
OR
activepdfdocconverterMatch3.8.4.0
OR
autonomykeyviewMatch2.0.0.2
OR
autonomykeyviewMatch10.3.0.0
OR
ibmlotus_notesMatch6.0
OR
ibmlotus_notesMatch6.5
OR
ibmlotus_notesMatch7.0
OR
ibmlotus_notesMatch7.0.2
OR
ibmlotus_notesMatch7.0.3
OR
symantecmail_securityMatch5.0microsoft_exchange
OR
symantecmail_securityMatch5.0.0smtp
OR
symantecmail_securityMatch5.0.1smtp
OR
symantecmail_securityMatch7.5domino
OR
symantecmail_security_applianceMatch5.0
VendorProductVersionCPE
activepdfdocconverter3.8.2_.5cpe:2.3:a:activepdf:docconverter:3.8.2_.5:*:*:*:*:*:*:*
activepdfdocconverter3.8.4.0cpe:2.3:a:activepdf:docconverter:3.8.4.0:*:*:*:*:*:*:*
autonomykeyview2.0.0.2cpe:2.3:a:autonomy:keyview:2.0.0.2:*:*:*:*:*:*:*
autonomykeyview10.3.0.0cpe:2.3:a:autonomy:keyview:10.3.0.0:*:*:*:*:*:*:*
ibmlotus_notes6.0cpe:2.3:a:ibm:lotus_notes:6.0:*:*:*:*:*:*:*
ibmlotus_notes6.5cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*
ibmlotus_notes7.0cpe:2.3:a:ibm:lotus_notes:7.0:*:*:*:*:*:*:*
ibmlotus_notes7.0.2cpe:2.3:a:ibm:lotus_notes:7.0.2:*:*:*:*:*:*:*
ibmlotus_notes7.0.3cpe:2.3:a:ibm:lotus_notes:7.0.3:*:*:*:*:*:*:*
symantecmail_security5.0cpe:2.3:a:symantec:mail_security:5.0:*:microsoft_exchange:*:*:*:*:*
Rows per page:
1-10 of 141

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.783

Percentile

98.3%