Lucene search

K
nvd[email protected]NVD:CVE-2005-0684
HistoryApr 25, 2005 - 4:00 a.m.

CVE-2005-0684

2005-04-2504:00:00
web.nvd.nist.gov
1

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.923

Percentile

99.0%

Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent (“%”) sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the getLockTokenHeader function in WDVHandler_CommonUtils.c.

Affected configurations

Nvd
Node
mysqlmaxdbMatch7.5.00
OR
mysqlmaxdbMatch7.5.00.08
OR
mysqlmaxdbMatch7.5.00.11
OR
mysqlmaxdbMatch7.5.00.12
OR
mysqlmaxdbMatch7.5.00.14
OR
mysqlmaxdbMatch7.5.00.15
OR
mysqlmaxdbMatch7.5.00.16
OR
mysqlmaxdbMatch7.5.00.18
OR
mysqlmaxdbMatch7.5.00.19
OR
mysqlmaxdbMatch7.5.00.23
VendorProductVersionCPE
mysqlmaxdb7.5.00cpe:2.3:a:mysql:maxdb:7.5.00:*:*:*:*:*:*:*
mysqlmaxdb7.5.00.08cpe:2.3:a:mysql:maxdb:7.5.00.08:*:*:*:*:*:*:*
mysqlmaxdb7.5.00.11cpe:2.3:a:mysql:maxdb:7.5.00.11:*:*:*:*:*:*:*
mysqlmaxdb7.5.00.12cpe:2.3:a:mysql:maxdb:7.5.00.12:*:*:*:*:*:*:*
mysqlmaxdb7.5.00.14cpe:2.3:a:mysql:maxdb:7.5.00.14:*:*:*:*:*:*:*
mysqlmaxdb7.5.00.15cpe:2.3:a:mysql:maxdb:7.5.00.15:*:*:*:*:*:*:*
mysqlmaxdb7.5.00.16cpe:2.3:a:mysql:maxdb:7.5.00.16:*:*:*:*:*:*:*
mysqlmaxdb7.5.00.18cpe:2.3:a:mysql:maxdb:7.5.00.18:*:*:*:*:*:*:*
mysqlmaxdb7.5.00.19cpe:2.3:a:mysql:maxdb:7.5.00.19:*:*:*:*:*:*:*
mysqlmaxdb7.5.00.23cpe:2.3:a:mysql:maxdb:7.5.00.23:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.923

Percentile

99.0%