Lucene search

K
cve[email protected]CVE-2013-1085
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-1085

2022-10-0316:14:47
CWE-119
web.nvd.nist.gov
108
cve
2013
1085
buffer overflow
nim
protocol
novell groupwise messenger
novell messenger
remote attackers
arbitrary code
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.3 High

AI Score

Confidence

Low

0.472 Medium

EPSS

Percentile

97.5%

Stack-based buffer overflow in the nim: protocol handler in Novell GroupWise Messenger 2.04 and earlier, and Novell Messenger 2.1.x and 2.2.x before 2.2.2, allows remote attackers to execute arbitrary code via an import command containing a long string in the filename parameter.

Affected configurations

NVD
Node
novellgroupwise_messengerRange2.0.4
OR
novellgroupwise_messengerMatch1.0.6
OR
novellgroupwise_messengerMatch2.0
OR
novellgroupwise_messengerMatch2.0.2
Node
novellmessengerRange2.1
Node
novellmessengerRange2.2.1
OR
novellmessengerMatch2.2.0

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.3 High

AI Score

Confidence

Low

0.472 Medium

EPSS

Percentile

97.5%