Lucene search

K
cveMitreCVE-2008-3606
HistoryAug 12, 2008 - 7:41 p.m.

CVE-2008-3606

2008-08-1219:41:00
CWE-119
mitre
web.nvd.nist.gov
34
cve-2008-3606
heap-based
buffer overflow
imap
qbik wingate
denial of service
remote code execution
nvd

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

8

Confidence

High

EPSS

0.075

Percentile

94.2%

Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possibly execute arbitrary code via a long argument to the LIST command. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
qbikwingateRange6.2.2
OR
qbikwingateMatch2.0
OR
qbikwingateMatch2.1
OR
qbikwingateMatch3.0
OR
qbikwingateMatch3.0.5
OR
qbikwingateMatch4.0.1
OR
qbikwingateMatch4.1beta_a
OR
qbikwingateMatch4.1.0
OR
qbikwingateMatch4.1.1
OR
qbikwingateMatch4.2.0
OR
qbikwingateMatch4.3.0
OR
qbikwingateMatch4.3.0beta_a
OR
qbikwingateMatch4.3.0beta_b
OR
qbikwingateMatch4.4.0
OR
qbikwingateMatch4.4.0beta_a
OR
qbikwingateMatch4.4.1
OR
qbikwingateMatch4.4.2
OR
qbikwingateMatch4.5.0beta_a
OR
qbikwingateMatch4.5.0beta_b
OR
qbikwingateMatch4.5.1
OR
qbikwingateMatch4.5.2
OR
qbikwingateMatch5.0
OR
qbikwingateMatch5.0.0
OR
qbikwingateMatch5.0.1
OR
qbikwingateMatch5.0.1.766
OR
qbikwingateMatch5.0.5
OR
qbikwingateMatch5.1
OR
qbikwingateMatch5.2
OR
qbikwingateMatch5.2.2
OR
qbikwingateMatch5.2.3
OR
qbikwingateMatch6.0
OR
qbikwingateMatch6.0.0.984
OR
qbikwingateMatch6.0.1.993
OR
qbikwingateMatch6.0.1.995
OR
qbikwingateMatch6.0.2.1000
OR
qbikwingateMatch6.0.2.1001
OR
qbikwingateMatch6.0.3.1005
OR
qbikwingateMatch6.0.4.1025
OR
qbikwingateMatch6.1.1.1077
OR
qbikwingateMatch6.1.2.1094
OR
qbikwingateMatch6.1.3.1096
OR
qbikwingateMatch6.1.4
OR
qbikwingateMatch6.2.1
OR
qbikwingateMatch6.2.2.1137
VendorProductVersionCPE
qbikwingate*cpe:2.3:a:qbik:wingate:*:*:*:*:*:*:*:*
qbikwingate2.0cpe:2.3:a:qbik:wingate:2.0:*:*:*:*:*:*:*
qbikwingate2.1cpe:2.3:a:qbik:wingate:2.1:*:*:*:*:*:*:*
qbikwingate3.0cpe:2.3:a:qbik:wingate:3.0:*:*:*:*:*:*:*
qbikwingate3.0.5cpe:2.3:a:qbik:wingate:3.0.5:*:*:*:*:*:*:*
qbikwingate4.0.1cpe:2.3:a:qbik:wingate:4.0.1:*:*:*:*:*:*:*
qbikwingate4.1cpe:2.3:a:qbik:wingate:4.1:beta_a:*:*:*:*:*:*
qbikwingate4.1.0cpe:2.3:a:qbik:wingate:4.1.0:*:*:*:*:*:*:*
qbikwingate4.1.1cpe:2.3:a:qbik:wingate:4.1.1:*:*:*:*:*:*:*
qbikwingate4.2.0cpe:2.3:a:qbik:wingate:4.2.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 441

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

8

Confidence

High

EPSS

0.075

Percentile

94.2%

Related for CVE-2008-3606