9.3
CVSSv2

CVE-2005-2618

Published: 31/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK prior to 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote malicious users to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename handled by kvarcve.dll, (3) a TAR archive with a long filename that is extracted to a directory with a long path handled by the TAR reader (tarrdr.dll), (4) an email that contains a long HTTP, FTP, or // link handled by the HTML speed reader (htmsr.dll) or (5) an email containing a crafted long link handled by the HTML speed reader (htmsr.dll).

Vulnerable Product Search on Vulmon Subscribe to Product

autonomy keyview export sdk

autonomy keyview filter sdk

ibm lotus notes 6.5

ibm lotus notes 6.5.1

autonomy keyview viewer sdk

ibm lotus notes 6.0.1

ibm lotus notes 6.5.2

ibm lotus notes 6.5.3

ibm lotus notes 6.5.4

ibm lotus notes 6.0.2

ibm lotus notes 6.0.3

ibm lotus notes 7.0

ibm lotus notes 6.0.4

ibm lotus notes 6.0.5