Lucene search

K
cve[email protected]CVE-2015-2063
HistoryMar 09, 2015 - 2:59 p.m.

CVE-2015-2063

2015-03-0914:59:09
CWE-189
web.nvd.nist.gov
39
cve-2015-2063
integer overflow
unace 1.2b
denial of service
nvd
buffer overflow

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.8 Medium

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.5%

Integer overflow in unace 1.2b allows remote attackers to cause a denial of service (crash) via a small file header in an ace archive, which triggers a buffer overflow.

Affected configurations

NVD
Node
winaceunaceMatch1.2b
CPENameOperatorVersion
winace:unacewinace unaceeq1.2b

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.8 Medium

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.5%