Lucene search

K
cve[email protected]CVE-2008-3865
HistoryJan 21, 2009 - 8:30 p.m.

CVE-2008-3865

2009-01-2120:30:00
CWE-119
web.nvd.nist.gov
19
cve-2008-3865
buffer overflow
trend micro
nsc
officescan
internet security
remote code execution
security vulnerability

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

Low

0.55 Medium

EPSS

Percentile

97.7%

Multiple heap-based buffer overflows in the ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allow remote attackers to execute arbitrary code via a packet with a small value in an unspecified size field.

Affected configurations

NVD
Node
trend_microinternet_security_2007
OR
trend_microinternet_security_2008Match17.0.1224
OR
trend_microofficescanMatch8.0sp1

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

Low

0.55 Medium

EPSS

Percentile

97.7%