Lucene search

K
cve[email protected]CVE-2008-3862
HistoryOct 23, 2008 - 10:00 p.m.

CVE-2008-3862

2008-10-2322:00:01
CWE-119
web.nvd.nist.gov
33
cve-2008-3862
trend micro officescan
buffer overflow
security vulnerability
cgi
remote code execution
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.55 Medium

EPSS

Percentile

97.7%

Stack-based buffer overflow in CGI programs in the server in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1374, and 8.0 SP1 Patch 1 before build 3110, allows remote attackers to execute arbitrary code via an HTTP POST request containing crafted form data, related to β€œparsing CGI requests.”

Affected configurations

NVD
Node
trend_microofficescanMatch7.3
OR
trend_microofficescanMatch8.0sp1

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.55 Medium

EPSS

Percentile

97.7%