René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

431 lines
15 KiB
JSON

{
"id": "CVE-2005-2127",
"sourceIdentifier": "secure@microsoft.com",
"published": "2005-08-19T04:00:00.000",
"lastModified": "2018-10-19T15:32:34.783",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the \"COM Object Instantiation Memory Corruption vulnerability.\""
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ati:catalyst_driver:*:*:*:*:*:*:*:*",
"matchCriteriaId": "62E822DD-6123-4CD8-9FE4-BC8A91D94F80"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:.net_framework:1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "1A927C9E-5CCC-4FC1-AE63-24B96A5FC51A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:.net_framework:1.1:sp1:*:*:*:*:*:*",
"matchCriteriaId": "0BF6AE15-EAC3-4100-A742-211026C79CCC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:.net_framework:1.1:sp2:*:*:*:*:*:*",
"matchCriteriaId": "A2804E22-FFF4-4301-8958-16B32CE5ECD1"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:.net_framework:1.1:sp3:*:*:*:*:*:*",
"matchCriteriaId": "B33B1B47-EEA0-4B1F-AC03-CAB56AB42DC7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:*:*:*:*:*:*:*:*",
"matchCriteriaId": "49AD45BF-8A91-4C87-AF15-D38D8468A4C5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:2000:*:*:*:*:*:*:*",
"matchCriteriaId": "A9A82D13-513C-46FA-AF51-0582233E230A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:2000:*:*:ja:*:*:*:*",
"matchCriteriaId": "757EC6C1-F5E2-45CD-9F7F-7760ECEDC842"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:2000:*:*:ko:*:*:*:*",
"matchCriteriaId": "59B1B68C-86F1-4FA4-9F82-3E8761ED1E74"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:2000:*:*:zh:*:*:*:*",
"matchCriteriaId": "716DDA05-D094-4837-852C-0511CDDD5ABC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:2000:sp1:*:*:*:*:*:*",
"matchCriteriaId": "3C54DDAF-8D7F-4A7D-9186-6048D4C850B2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:2000:sp2:*:*:*:*:*:*",
"matchCriteriaId": "67388076-420D-4327-A436-329177EA6F42"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:2000:sp3:*:*:*:*:*:*",
"matchCriteriaId": "4891122F-AD7F-45E6-98C6-833227916F6B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:xp:sp1:*:*:*:*:*:*",
"matchCriteriaId": "5AB85A3C-EFA3-485D-84C5-7976718AEAE0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:xp:sp2:*:*:*:*:*:*",
"matchCriteriaId": "9D02D769-061D-44A5-B019-F4E653DF615A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:office:xp:sp3:*:*:*:*:*:*",
"matchCriteriaId": "79BA1175-7F02-4435-AEA6-1BA8AADEB7EF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:project:98:*:*:*:*:*:*:*",
"matchCriteriaId": "77BFDC2A-4AE1-4FC8-ABA7-0400D46EA587"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:project:2000:*:*:*:*:*:*:*",
"matchCriteriaId": "3F09162C-01F0-4056-94D3-995713F92AE9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:project:2002:*:*:*:*:*:*:*",
"matchCriteriaId": "2AE2D3E0-49E4-410E-B63A-753BDE8995BB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:project:2002:sp1:*:*:*:*:*:*",
"matchCriteriaId": "9B14AE8E-1BFF-4458-87CC-357957F18F8A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:project:2003:*:*:*:*:*:*:*",
"matchCriteriaId": "34EFAEFE-2BDE-4111-91F5-E9F75ADFA920"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:project:2003:sp1:*:*:*:*:*:*",
"matchCriteriaId": "AC1DA2B8-C41B-4EB9-A58F-E4E63F695A55"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2000:sr1:*:*:enterprise:*:*:*",
"matchCriteriaId": "B4EC96E0-8D7C-4C72-8F04-97B0B675306E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2002:*:*:*:*:*:*:*",
"matchCriteriaId": "8E24DF34-F4A8-4C28-9593-F019FE3E3BA2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2002:*:*:*:professional:*:*:*",
"matchCriteriaId": "FF41DACB-D707-4ED3-BA2E-2EEABC17FC4D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2002:sp1:*:*:*:*:*:*",
"matchCriteriaId": "70D447B9-4604-447C-88FC-F5DC8F77603C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2002:sp2:*:*:*:*:*:*",
"matchCriteriaId": "D0D2C5C3-225C-49DC-B9C7-C5BC05900F2E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2002:sp2:*:*:professional:*:*:*",
"matchCriteriaId": "F6E69C81-2894-4319-9FBD-60AE719942E9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2002:sp2:*:*:standard:*:*:*",
"matchCriteriaId": "8BC60369-95D2-475B-9FDA-5D1C13FEE8DF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2003:*:*:*:*:*:*:*",
"matchCriteriaId": "511E22C6-DB04-44A0-906D-F432DD42CA5C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2003:*:*:*:professional:*:*:*",
"matchCriteriaId": "9BF7D109-38E6-4FEE-8F9B-9A481D50DCFA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2003:*:*:*:standard:*:*:*",
"matchCriteriaId": "3D931561-2312-4770-B418-FB622856DF34"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2003:sp1:*:*:*:*:*:*",
"matchCriteriaId": "6FBEFBED-72F3-447B-8164-9E5C16828484"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_studio_.net:2002:gold:*:*:*:*:*:*",
"matchCriteriaId": "E17BD019-DD35-413E-ACBA-2E77C8A1247D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_studio_.net:2003:*:*:*:enterprise_architect:*:*:*",
"matchCriteriaId": "A681100F-9DE5-4BE6-ADE9-64A3808C7CDE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_studio_.net:2003:gold:*:*:*:*:*:*",
"matchCriteriaId": "B9E6C132-4F4B-4FB0-9DDC-DD9750D8552D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_studio_.net:gold:*:*:*:academic:*:*:*",
"matchCriteriaId": "AEC99110-8EC1-4FEC-9535-B27AF1965DBF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_studio_.net:gold:*:*:*:enterprise_architect:*:*:*",
"matchCriteriaId": "B35FE238-4380-41C7-A956-EA3F2D5F9159"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_studio_.net:gold:*:*:*:enterprise_developer:*:*:*",
"matchCriteriaId": "A8E772B4-8E7D-4D35-8C59-5959123AA572"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_studio_.net:gold:*:*:*:professional:*:*:*",
"matchCriteriaId": "4AFEC24E-5FA5-4653-BBAA-AFEBCC3F149B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visual_studio_.net:gold:*:*:*:trial:*:*:*",
"matchCriteriaId": "D451D000-00DC-46A9-9D1E-2C715D6D1787"
}
]
}
]
}
],
"references": [
{
"url": "http://isc.sans.org/diary.php?date=2005-08-18",
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "http://securityreason.com/securityalert/72",
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "http://securitytracker.com/id?1014727",
"source": "secure@microsoft.com",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory",
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf",
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "http://www.kb.cert.org/vuls/id/740372",
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
},
{
"url": "http://www.kb.cert.org/vuls/id/898241",
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
},
{
"url": "http://www.kb.cert.org/vuls/id/959049",
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
},
{
"url": "http://www.microsoft.com/technet/security/advisory/906267.mspx",
"source": "secure@microsoft.com",
"tags": [
"Mitigation",
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/archive/1/470690/100/0/threaded",
"source": "secure@microsoft.com"
},
{
"url": "http://www.securityfocus.com/bid/14594",
"source": "secure@microsoft.com",
"tags": [
"Exploit",
"Patch",
"VDB Entry",
"Third Party Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/15061",
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA05-284A.html",
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA05-347A.html",
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA06-220A.html",
"source": "secure@microsoft.com",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
},
{
"url": "http://www.vupen.com/english/advisories/2005/1450",
"source": "secure@microsoft.com",
"tags": [
"Broken Link"
]
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-052",
"source": "secure@microsoft.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21895",
"source": "secure@microsoft.com",
"tags": [
"VDB Entry"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34754",
"source": "secure@microsoft.com",
"tags": [
"VDB Entry"
]
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1155",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1454",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1464",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1468",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1535",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1538",
"source": "secure@microsoft.com"
}
]
}