Lucene search

K
cveFlexeraCVE-2007-6020
HistoryApr 10, 2008 - 6:05 p.m.

CVE-2007-6020

2008-04-1018:05:00
CWE-119
flexera
web.nvd.nist.gov
27
cve-2007-6020
stack-based buffer overflows
foliosr.dll
autonomy keyview
remote code execution
ibm lotus notes
symantec mail security
activepdf docconverter
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.606

Percentile

97.9%

Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a long attribute value in a (1) DI, (2) FD, (3) FT, (4) JD, (5) JL, (6) LE, (7) OB, (8) OD, (9) OL, (10) PN, (11) PS, (12) PW, (13) RD, (14) QL, or (15) TS tag in a .fff file.

Affected configurations

Nvd
Node
activepdfdocconverterMatch3.8.4.0
OR
autonomykeyviewMatch2.0.0.2
OR
autonomykeyviewMatch10.3.0.0
OR
ibmlotus_notesMatch6.0
OR
ibmlotus_notesMatch6.5
OR
ibmlotus_notesMatch7.0
OR
ibmlotus_notesMatch7.0.2
OR
ibmlotus_notesMatch7.0.3
OR
symantecmail_securityMatch5.0microsoft_exchange
OR
symantecmail_securityMatch5.0.0smtp
OR
symantecmail_securityMatch5.0.1smtp
OR
symantecmail_securityMatch7.5domino
OR
symantecmail_security_applianceMatch5.0
VendorProductVersionCPE
activepdfdocconverter3.8.4.0cpe:2.3:a:activepdf:docconverter:3.8.4.0:*:*:*:*:*:*:*
autonomykeyview2.0.0.2cpe:2.3:a:autonomy:keyview:2.0.0.2:*:*:*:*:*:*:*
autonomykeyview10.3.0.0cpe:2.3:a:autonomy:keyview:10.3.0.0:*:*:*:*:*:*:*
ibmlotus_notes6.0cpe:2.3:a:ibm:lotus_notes:6.0:*:*:*:*:*:*:*
ibmlotus_notes6.5cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*
ibmlotus_notes7.0cpe:2.3:a:ibm:lotus_notes:7.0:*:*:*:*:*:*:*
ibmlotus_notes7.0.2cpe:2.3:a:ibm:lotus_notes:7.0.2:*:*:*:*:*:*:*
ibmlotus_notes7.0.3cpe:2.3:a:ibm:lotus_notes:7.0.3:*:*:*:*:*:*:*
symantecmail_security5.0cpe:2.3:a:symantec:mail_security:5.0:*:microsoft_exchange:*:*:*:*:*
symantecmail_security5.0.0cpe:2.3:a:symantec:mail_security:5.0.0:*:smtp:*:*:*:*:*
Rows per page:
1-10 of 131

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.606

Percentile

97.9%