CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
98.7%
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910.
Vendor | Product | Version | CPE |
---|---|---|---|
activepdf | docconverter | 3.8.2_.5 | cpe:2.3:a:activepdf:docconverter:3.8.2_.5:*:*:*:*:*:*:* |
autonomy | keyview_export_sdk | * | cpe:2.3:a:autonomy:keyview_export_sdk:*:*:*:*:*:*:*:* |
autonomy | keyview_filter_sdk | * | cpe:2.3:a:autonomy:keyview_filter_sdk:*:*:*:*:*:*:*:* |
autonomy | keyview_viewer_sdk | * | cpe:2.3:a:autonomy:keyview_viewer_sdk:*:*:*:*:*:*:*:* |
ibm | lotus_notes | * | cpe:2.3:a:ibm:lotus_notes:*:*:*:*:*:*:*:* |
symantec | mail_security | 5.0 | cpe:2.3:a:symantec:mail_security:5.0:*:appliance:*:*:*:*:* |
symantec | mail_security | 5.0 | cpe:2.3:a:symantec:mail_security:5.0:*:microsoft_exchange:*:*:*:*:* |
symantec | mail_security | 5.0.0 | cpe:2.3:a:symantec:mail_security:5.0.0:*:smtp:*:*:*:*:* |
symantec | mail_security | 5.0.0.24 | cpe:2.3:a:symantec:mail_security:5.0.0.24:*:appliance:*:*:*:*:* |
symantec | mail_security | 5.0.1 | cpe:2.3:a:symantec:mail_security:5.0.1:*:smtp:*:*:*:*:* |
secunia.com/advisories/27304
securityreason.com/securityalert/3357
securityresponse.symantec.com/avcenter/security/Content/2007.11.01c.html
securitytracker.com/id?1018853
securitytracker.com/id?1018886
vuln.sg/lotusnotes702-en.html
vuln.sg/lotusnotes702doc-en.html
vuln.sg/lotusnotes702mif-en.html
vuln.sg/lotusnotes702sam-en.html
www-1.ibm.com/support/docview.wss?rs=899&uid=swg21271111
www-1.ibm.com/support/docview.wss?rs=899&uid=swg21272836
www.securityfocus.com/archive/1/482664
www.securityfocus.com/archive/1/483102/100/0/threaded
www.securityfocus.com/bid/26175
www.vupen.com/english/advisories/2007/3596
www.vupen.com/english/advisories/2007/3697
www.zerodayinitiative.com/advisories/ZDI-07-059.html