Описание
Integer underflow in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted size for an unspecified record type, which triggers a heap-based buffer overflow.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:autonomy:keyview_export_sdk:10.4:*:*:*:*:*:*:*
cpe:2.3:a:autonomy:keyview_export_sdk:10.9:*:*:*:*:*:*:*
cpe:2.3:a:autonomy:keyview_filter_sdk:10.4:*:*:*:*:*:*:*
cpe:2.3:a:autonomy:keyview_filter_sdk:10.9:*:*:*:*:*:*:*
cpe:2.3:a:autonomy:keyview_viewer_sdk:10.4:*:*:*:*:*:*:*
cpe:2.3:a:autonomy:keyview_viewer_sdk:10.9:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02581
Низкий
9.3 Critical
CVSS2
Дефекты
CWE-189
Связанные уязвимости
github
больше 3 лет назад
Integer underflow in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted size for an unspecified record type, which triggers a heap-based buffer overflow.
EPSS
Процентиль: 85%
0.02581
Низкий
9.3 Critical
CVSS2
Дефекты
CWE-189