Lucene search

K
nvd[email protected]NVD:CVE-2008-0064
HistoryJan 31, 2008 - 8:00 p.m.

CVE-2008-0064

2008-01-3120:00:00
CWE-119
web.nvd.nist.gov

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.086

Percentile

94.6%

Stack-based buffer overflow in Pierre-emmanuel Gougelet (1) XnView 1.91 and 1.92, (2) NConvert 4.85, and (3) libgfl280.dll in GFL SDK 2.870 for Windows allows user-assisted remote attackers to execute arbitrary code via a crafted Radiance RGBE (.hdr) file.

Affected configurations

Nvd
Node
pierreegougeletgfl_sdkMatch2.870windows
OR
pierreegougeletnconvertRange4.85
OR
pierreegougeletxnviewRange1.91
OR
pierreegougeletxnviewRange1.92
VendorProductVersionCPE
pierreegougeletgfl_sdk2.870cpe:2.3:a:pierreegougelet:gfl_sdk:2.870:*:windows:*:*:*:*:*
pierreegougeletnconvert*cpe:2.3:a:pierreegougelet:nconvert:*:*:*:*:*:*:*:*
pierreegougeletxnview*cpe:2.3:a:pierreegougelet:xnview:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.086

Percentile

94.6%

Related for NVD:CVE-2008-0064