Lucene search

K
nvd[email protected]NVD:CVE-2007-5406
HistoryApr 10, 2008 - 6:05 p.m.

CVE-2007-5406

2008-04-1018:05:00
web.nvd.nist.gov
3

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

High

EPSS

0.334

Percentile

97.1%

kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, does not properly parse long tokens, which allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted .ag file.

Affected configurations

Nvd
Node
ibmlotus_notesMatch6.0
OR
ibmlotus_notesMatch6.5
OR
ibmlotus_notesMatch7.0
OR
ibmlotus_notesMatch8.0
OR
ibmlotus_notesMatch8.0.1
OR
symantecmail_securityRange7.5domino
OR
symantecmail_securityMatch5.0
OR
symantecmail_securityMatch5.0microsoft_exchange
OR
symantecmail_securityMatch5.0.0smtp
OR
symantecmail_securityMatch5.0.1smtp
AND
autonomykeyview
VendorProductVersionCPE
ibmlotus_notes6.0cpe:2.3:a:ibm:lotus_notes:6.0:*:*:*:*:*:*:*
ibmlotus_notes6.5cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*
ibmlotus_notes7.0cpe:2.3:a:ibm:lotus_notes:7.0:*:*:*:*:*:*:*
ibmlotus_notes8.0cpe:2.3:a:ibm:lotus_notes:8.0:*:*:*:*:*:*:*
ibmlotus_notes8.0.1cpe:2.3:a:ibm:lotus_notes:8.0.1:*:*:*:*:*:*:*
symantecmail_security*cpe:2.3:a:symantec:mail_security:*:*:domino:*:*:*:*:*
symantecmail_security5.0cpe:2.3:a:symantec:mail_security:5.0:*:*:*:*:*:*:*
symantecmail_security5.0cpe:2.3:a:symantec:mail_security:5.0:*:microsoft_exchange:*:*:*:*:*
symantecmail_security5.0.0cpe:2.3:a:symantec:mail_security:5.0.0:*:smtp:*:*:*:*:*
symantecmail_security5.0.1cpe:2.3:a:symantec:mail_security:5.0.1:*:smtp:*:*:*:*:*
Rows per page:
1-10 of 111

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

High

EPSS

0.334

Percentile

97.1%

Related for NVD:CVE-2007-5406