Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-1929

Опубликовано: 14 дек. 2005
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer requests. NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load. As such, this might not be a vulnerability in Trend Micro's product.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:trend_micro:serverprotect:*:*:emc:*:*:*:*:*
Версия до 5.58 (включая)

EPSS

Процентиль: 89%
0.04754
Низкий

7.5 High

CVSS2

Дефекты

CWE-119

Связанные уязвимости

github
почти 4 года назад

Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer requests. NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load. As such, this might not be a vulnerability in Trend Micro's product.

EPSS

Процентиль: 89%
0.04754
Низкий

7.5 High

CVSS2

Дефекты

CWE-119