René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

100 lines
3.2 KiB
JSON

{
"id": "CVE-2009-0098",
"sourceIdentifier": "secure@microsoft.com",
"published": "2009-02-10T22:30:00.343",
"lastModified": "2018-10-12T21:49:41.410",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka \"Memory Corruption Vulnerability.\""
},
{
"lang": "es",
"value": "Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2 y Exchange Server 2007 SP1; no interpreta adecuadamente las propiedades de Transport Neutral Encapsulation (TNEF), esto permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de un mensaje TNEF manipulado. Tambi\u00e9n se conoce como \"Vulnerabilidad de Corrupci\u00f3n de Memoria\"."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 9.3
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.6,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-399"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*",
"matchCriteriaId": "E88E31D4-1120-4A18-BA65-E2C96B35E599"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:exchange_server:2003:sp2:*:*:*:*:*:*",
"matchCriteriaId": "71A2E549-5F21-4842-BEB3-380CD4029C16"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:exchange_server:2007:sp1:*:*:*:*:*:*",
"matchCriteriaId": "9C218952-1BB8-4915-B31F-9D23543FC83E"
}
]
}
]
}
],
"references": [
{
"url": "http://www.us-cert.gov/cas/techalerts/TA09-041A.html",
"source": "secure@microsoft.com",
"tags": [
"US Government Resource"
]
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-003",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6114",
"source": "secure@microsoft.com"
}
]
}