Lucene search

K
cve[email protected]CVE-2009-3735
HistoryFeb 11, 2010 - 5:30 p.m.

CVE-2009-3735

2010-02-1117:30:00
CWE-94
web.nvd.nist.gov
23
cve-2009-3735
activescan
activex control
panda activescan
remote code execution
digital signature
arbitrary url
software download

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

Low

0.104 Low

EPSS

Percentile

95.0%

The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in an as2guiie.cab archive located at an arbitrary URL, and does not verify the archive’s digital signature before installation, which allows remote attackers to execute arbitrary code via a URL argument to an unspecified method.

Affected configurations

NVD
Node
pandapanda_activescanMatch2.0

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

Low

0.104 Low

EPSS

Percentile

95.0%

Related for CVE-2009-3735