Lucene search

K
cveFlexeraCVE-2010-1525
HistoryAug 17, 2010 - 8:00 p.m.

CVE-2010-1525

2010-08-1720:00:03
CWE-189
flexera
web.nvd.nist.gov
29
cve
2010
1525
integer underflow
spreadsheet
lotus 123
autonomy keyview
dos
code execution
buffer overflow

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

High

EPSS

0.036

Percentile

91.8%

Integer underflow in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted size for an unspecified record type, which triggers a heap-based buffer overflow.

Affected configurations

Nvd
Node
autonomykeyview_export_sdkMatch10.4
OR
autonomykeyview_export_sdkMatch10.9
OR
autonomykeyview_filter_sdkMatch10.4
OR
autonomykeyview_filter_sdkMatch10.9
OR
autonomykeyview_viewer_sdkMatch10.4
OR
autonomykeyview_viewer_sdkMatch10.9
VendorProductVersionCPE
autonomykeyview_export_sdk10.4cpe:2.3:a:autonomy:keyview_export_sdk:10.4:*:*:*:*:*:*:*
autonomykeyview_export_sdk10.9cpe:2.3:a:autonomy:keyview_export_sdk:10.9:*:*:*:*:*:*:*
autonomykeyview_filter_sdk10.4cpe:2.3:a:autonomy:keyview_filter_sdk:10.4:*:*:*:*:*:*:*
autonomykeyview_filter_sdk10.9cpe:2.3:a:autonomy:keyview_filter_sdk:10.9:*:*:*:*:*:*:*
autonomykeyview_viewer_sdk10.4cpe:2.3:a:autonomy:keyview_viewer_sdk:10.4:*:*:*:*:*:*:*
autonomykeyview_viewer_sdk10.9cpe:2.3:a:autonomy:keyview_viewer_sdk:10.9:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

High

EPSS

0.036

Percentile

91.8%