Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-4880

Опубликовано: 28 сент. 2007
Источник: nvd
CVSS2: 10
EPSS Высокий

Описание

Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:tivoli_storage_manager_client:5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager_client:5.1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager_client:5.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager_client:5.2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager_client:5.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager_client:5.3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager_client:5.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_storage_manager_client:5.4.1.1:*:*:*:*:*:*:*

EPSS

Процентиль: 100%
0.88938
Высокий

10 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

github
почти 4 года назад

Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via crafted HTTP headers, aka IC52905.

EPSS

Процентиль: 100%
0.88938
Высокий

10 Critical

CVSS2

Дефекты

CWE-119