Lucene search

K
cveFlexeraCVE-2008-1101
HistoryApr 10, 2008 - 6:05 p.m.

CVE-2008-1101

2008-04-1018:05:00
CWE-119
flexera
web.nvd.nist.gov
32
cve-2008-1101
buffer overflow
kvdocve.dll
keyview
autonomy
verity
ibm lotus notes
remote code execution
html
img element

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.514

Percentile

97.6%

Buffer overflow in kvdocve.dll in the KeyView document viewing engine in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allows remote attackers to execute arbitrary code via a long pathname, as demonstrated by a long SRC attribute of an IMG element in an HTML document.

Affected configurations

Nvd
Node
autonomykeyviewMatch2.0.0.2
OR
autonomykeyviewMatch10.3.0.0
OR
ibmlotus_notesMatch6.0
OR
ibmlotus_notesMatch6.5
OR
ibmlotus_notesMatch7.0
OR
ibmlotus_notesMatch7.0.2
OR
ibmlotus_notesMatch7.0.3
VendorProductVersionCPE
autonomykeyview2.0.0.2cpe:2.3:a:autonomy:keyview:2.0.0.2:*:*:*:*:*:*:*
autonomykeyview10.3.0.0cpe:2.3:a:autonomy:keyview:10.3.0.0:*:*:*:*:*:*:*
ibmlotus_notes6.0cpe:2.3:a:ibm:lotus_notes:6.0:*:*:*:*:*:*:*
ibmlotus_notes6.5cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*
ibmlotus_notes7.0cpe:2.3:a:ibm:lotus_notes:7.0:*:*:*:*:*:*:*
ibmlotus_notes7.0.2cpe:2.3:a:ibm:lotus_notes:7.0.2:*:*:*:*:*:*:*
ibmlotus_notes7.0.3cpe:2.3:a:ibm:lotus_notes:7.0.3:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.514

Percentile

97.6%