2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2005-2619" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2005-12-31T05:00:00.000" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-20T23:59:58.973" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when generating a preview."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:C/I:C/A:C" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 9.3 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "COMPLETE" ,
"integrityImpact" : "COMPLETE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "COMPLETE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 10.0 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : true ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-22"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:autonomy:keyview_export_sdk:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E4CD7AAC-E4E2-47E4-A34D-47C670FA6254"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:autonomy:keyview_filter_sdk:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "754BD2C9-2100-4B21-B164-47487434D9E8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:autonomy:keyview_viewer_sdk:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7B6DDCD8-B9AD-4757-A067-CF99372D7326"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:lotus_notes:6.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "55D037CC-1207-48E2-882E-8B236EE7138F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:lotus_notes:6.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5059BEF2-84EB-4B5F-84F5-9E3200B068F3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:lotus_notes:6.0.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AB71B7AA-957B-46A6-9BC9-CE23EC721189"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:lotus_notes:6.0.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "46CF28C0-51AD-4783-B1F0-205DF64D133A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:lotus_notes:6.0.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9C0015A2-A70E-4B0C-B59A-44F5F611293D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1360A50E-C1E1-4690-874A-04CC7C1A77CC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:lotus_notes:6.5.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D94927A9-61FD-459F-9A6D-E581A4AF505C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:lotus_notes:6.5.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D3B32BA2-9EB7-4294-A857-226A5B1CC401"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:lotus_notes:6.5.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EF64CA16-6C20-42E1-BA68-BD63A873BFA9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:lotus_notes:6.5.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "12D7DD7B-CA90-44A5-9B7B-4A4985150689"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:lotus_notes:7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "68AEB13D-C7C6-426F-8484-85EFF7245DF5"
}
]
}
]
}
] ,
"references" : [
2024-04-04 08:46:00 +00:00
{
"url" : "http://secunia.com/advisories/16100" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://secunia.com/advisories/16280" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://secunia.com/secunia_research/2005-30/advisory/" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://secunia.com/secunia_research/2005-66/advisory/" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://securitytracker.com/id?1015657" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch"
]
} ,
{
"url" : "http://www-1.ibm.com/support/docview.wss?rs=475&uid=swg21229918" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch"
]
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://www.osvdb.org/23066" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch"
]
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://www.securityfocus.com/archive/1/424717/100/0/threaded" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.securityfocus.com/bid/16576" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://www.vupen.com/english/advisories/2006/0500" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24637" ,
"source" : "cve@mitre.org"
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://secunia.com/advisories/16100" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://secunia.com/advisories/16280" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://secunia.com/secunia_research/2005-30/advisory/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://secunia.com/secunia_research/2005-66/advisory/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://securitytracker.com/id?1015657" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
} ,
{
"url" : "http://www-1.ibm.com/support/docview.wss?rs=475&uid=swg21229918" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
} ,
{
"url" : "http://www.osvdb.org/23066" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
} ,
{
"url" : "http://www.securityfocus.com/archive/1/424717/100/0/threaded" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.securityfocus.com/bid/16576" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://www.vupen.com/english/advisories/2006/0500" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/24637" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}