Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-1525

Опубликовано: 17 авг. 2010
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Integer underflow in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted size for an unspecified record type, which triggers a heap-based buffer overflow.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:autonomy:keyview_export_sdk:10.4:*:*:*:*:*:*:*
cpe:2.3:a:autonomy:keyview_export_sdk:10.9:*:*:*:*:*:*:*
cpe:2.3:a:autonomy:keyview_filter_sdk:10.4:*:*:*:*:*:*:*
cpe:2.3:a:autonomy:keyview_filter_sdk:10.9:*:*:*:*:*:*:*
cpe:2.3:a:autonomy:keyview_viewer_sdk:10.4:*:*:*:*:*:*:*
cpe:2.3:a:autonomy:keyview_viewer_sdk:10.9:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02581
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-189

Связанные уязвимости

github
больше 3 лет назад

Integer underflow in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted size for an unspecified record type, which triggers a heap-based buffer overflow.

EPSS

Процентиль: 85%
0.02581
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-189