Lucene search

K
cveFlexeraCVE-2008-0066
HistoryApr 10, 2008 - 6:05 p.m.

CVE-2008-0066

2008-04-1018:05:00
CWE-119
flexera
web.nvd.nist.gov
26
cve-2008-0066
buffer overflow
htmsr.dll
autonomy keyview
html speed reader
ibm lotus notes 7.0.2
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.334

Percentile

97.1%

Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allow remote attackers to execute arbitrary code via an HTML document with (1) “large chunks of data,” or a long URL in the (2) BACKGROUND attribute of a BODY element or (3) SRC attribute of an IMG element.

Affected configurations

Nvd
Node
autonomykeyview
OR
ibmlotus_notesMatch7.0.2
OR
ibmlotus_notesMatch7.0.3
VendorProductVersionCPE
autonomykeyview*cpe:2.3:a:autonomy:keyview:*:*:*:*:*:*:*:*
ibmlotus_notes7.0.2cpe:2.3:a:ibm:lotus_notes:7.0.2:*:*:*:*:*:*:*
ibmlotus_notes7.0.3cpe:2.3:a:ibm:lotus_notes:7.0.3:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.334

Percentile

97.1%