Lucene search

K
cveMitreCVE-2009-3032
HistoryMar 05, 2010 - 7:30 p.m.

CVE-2009-3032

2010-03-0519:30:00
CWE-189
mitre
web.nvd.nist.gov
43
cve-2009-3032
integer overflow
autonomy keyview filter sdk
ibm lotus notes
symantec mail security
ole document
buffer overflow

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.004

Percentile

75.2%

Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.

Affected configurations

Nvd
Node
ibmlotus_notesMatch8.5
OR
symantecbrightmail_gatewayMatch8.0
OR
symantecdata_loss_prevention_detection_serversMatch8.1.1linux
OR
symantecdata_loss_prevention_detection_serversMatch8.1.1windows
OR
symantecdata_loss_prevention_detection_serversMatch9.0.1linux
OR
symantecdata_loss_prevention_detection_serversMatch9.0.1windows
OR
symantecdata_loss_prevention_detection_serversMatch10.0linux
OR
symantecdata_loss_prevention_detection_serversMatch10.0windows
OR
symantecdata_loss_prevention_endpoint_agentsMatch8.1.1
OR
symantecdata_loss_prevention_endpoint_agentsMatch9.0.1
OR
symantecdata_loss_prevention_endpoint_agentsMatch10.0
OR
symantecim_manager_2007
OR
symantecmail_securityMatch5.0.0smtp
OR
symantecmail_securityMatch5.0.1.181smtp
OR
symantecmail_securityMatch5.0.1.182smtp
OR
symantecmail_securityMatch5.0.1.189smtp
OR
symantecmail_securityMatch5.0.11microsoft_exchange
OR
symantecmail_securityMatch5.0.12microsoft_exchange
OR
symantecmail_securityMatch5.0.13microsoft_exchange
OR
symantecmail_securityMatch6.0.6microsoft_exchange
OR
symantecmail_securityMatch6.0.7microsoft_exchange
OR
symantecmail_securityMatch6.0.8microsoft_exchange
OR
symantecmail_securityMatch7.5.3.25domino
OR
symantecmail_securityMatch7.5.4.29domino
OR
symantecmail_securityMatch7.5.5.32domino
OR
symantecmail_securityMatch7.5.6domino
OR
symantecmail_securityMatch7.5.7domino
OR
symantecmail_securityMatch7.5.8domino
OR
symantecmail_securityMatch8.0domino
OR
symantecmail_securityMatch8.0.1domino
OR
symantecmail_securityMatch8.0.2domino
VendorProductVersionCPE
ibmlotus_notes8.5cpe:2.3:a:ibm:lotus_notes:8.5:*:*:*:*:*:*:*
symantecbrightmail_gateway8.0cpe:2.3:a:symantec:brightmail_gateway:8.0:*:*:*:*:*:*:*
symantecdata_loss_prevention_detection_servers8.1.1cpe:2.3:a:symantec:data_loss_prevention_detection_servers:8.1.1:*:linux:*:*:*:*:*
symantecdata_loss_prevention_detection_servers8.1.1cpe:2.3:a:symantec:data_loss_prevention_detection_servers:8.1.1:*:windows:*:*:*:*:*
symantecdata_loss_prevention_detection_servers9.0.1cpe:2.3:a:symantec:data_loss_prevention_detection_servers:9.0.1:*:linux:*:*:*:*:*
symantecdata_loss_prevention_detection_servers9.0.1cpe:2.3:a:symantec:data_loss_prevention_detection_servers:9.0.1:*:windows:*:*:*:*:*
symantecdata_loss_prevention_detection_servers10.0cpe:2.3:a:symantec:data_loss_prevention_detection_servers:10.0:*:linux:*:*:*:*:*
symantecdata_loss_prevention_detection_servers10.0cpe:2.3:a:symantec:data_loss_prevention_detection_servers:10.0:*:windows:*:*:*:*:*
symantecdata_loss_prevention_endpoint_agents8.1.1cpe:2.3:a:symantec:data_loss_prevention_endpoint_agents:8.1.1:*:*:*:*:*:*:*
symantecdata_loss_prevention_endpoint_agents9.0.1cpe:2.3:a:symantec:data_loss_prevention_endpoint_agents:9.0.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 311

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.004

Percentile

75.2%