2024-07-14 02:06:08 +00:00

110 lines
3.0 KiB
JSON

{
"id": "CVE-2007-5155",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-10-01T05:17:00.000",
"lastModified": "2017-07-29T01:33:25.707",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "IceGUI.DLL in ICEOWS 4.20b invokes a function with incorrect arguments, which allows user-assisted remote attackers to execute arbitrary code via a long filename in the header of an ACE archive, which triggers a stack-based buffer overflow."
},
{
"lang": "es",
"value": "IceGUI.DLL en ICEOWS 4.20b invoca una funci\u00f3n con argumentos incorrectos, lo cual permite a atacantes remotos con la intervenci\u00f3n del usuario ejecutar c\u00f3digo de su elecci\u00f3n mediante un nombre de archivo largo en la cabecera de un archivo ACE, lo cual dispara un desbordamiento de b\u00fafer basado en pila."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 9.3
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.6,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-119"
},
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:iceows:iceows:4.20b:*:*:*:*:*:*:*",
"matchCriteriaId": "AE94F368-73F0-43CA-B292-F5362C749CF7"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/41381",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26973",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://vuln.sg/iceows420b-en.html",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.securityfocus.com/bid/25844",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/3312",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36843",
"source": "cve@mitre.org"
}
]
}