Lucene search

K
nvd[email protected]NVD:CVE-2007-0160
HistoryJan 10, 2007 - 12:28 a.m.

CVE-2007-0160

2007-01-1000:28:00
CWE-119
web.nvd.nist.gov
3

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

High

EPSS

0.081

Percentile

94.3%

Stack-based buffer overflow in the LiveJournal support (hooks/ljhook.cc) in CenterICQ 4.9.11 through 4.21.0, when using unofficial LiveJournal servers, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by adding the victim as a friend and using long (1) username and (2) real name strings.

Affected configurations

Nvd
Node
centericqcentericqMatch4.9.11
OR
centericqcentericqMatch4.9.12
OR
centericqcentericqMatch4.12
OR
centericqcentericqMatch4.13
OR
centericqcentericqMatch4.14
OR
centericqcentericqMatch4.20
OR
centericqcentericqMatch4.21
VendorProductVersionCPE
centericqcentericq4.9.11cpe:2.3:a:centericq:centericq:4.9.11:*:*:*:*:*:*:*
centericqcentericq4.9.12cpe:2.3:a:centericq:centericq:4.9.12:*:*:*:*:*:*:*
centericqcentericq4.12cpe:2.3:a:centericq:centericq:4.12:*:*:*:*:*:*:*
centericqcentericq4.13cpe:2.3:a:centericq:centericq:4.13:*:*:*:*:*:*:*
centericqcentericq4.14cpe:2.3:a:centericq:centericq:4.14:*:*:*:*:*:*:*
centericqcentericq4.20cpe:2.3:a:centericq:centericq:4.20:*:*:*:*:*:*:*
centericqcentericq4.21cpe:2.3:a:centericq:centericq:4.21:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

High

EPSS

0.081

Percentile

94.3%