3 results (0.008 seconds)

CVSS: 10.0EPSS: 30%CPEs: 1EXPL: 0

Heap-based buffer overflow in WinAce 2.65 and earlier, and possibly other versions before 2.69, allows user-assisted remote attackers to execute arbitrary code via a long filename in a compressed UUE archive. Desbordamiento de búfer basado en montículo en WinAce 2.65 y versiones anteriores, y posiblemente otras versiones anteriores a 2.69, permite a atacantes remotos con la complicidad del usuario ejecutar código de su elección mediante un nombre de fichero largo en un archivo comprimido UUE. • http://jvn.jp/jp/JVN%2344736880/index.html http://jvndb.jvn.jp/contents/ja/2007/JVNDB-2007-000822.html http://osvdb.org/40267 http://secunia.com/advisories/28215 http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20071225 http://www.securityfocus.com/bid/27017 http://www.vupen.com/english/advisories/2007/4312 https://exchange.xforce.ibmcloud.com/vulnerabilities/39268 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.8EPSS: 1%CPEs: 3EXPL: 1

WinAce allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. WinAce permite a atacantes remotos provocar una denegación de servicio (bucle infinito) mediante un archivo ZOO con una estructura de entrada de directorio (direntry structure) que apunta a un fichero anterior. • http://osvdb.org/41750 http://securityreason.com/securityalert/2680 http://www.securityfocus.com/archive/1/467646/100/0/threaded http://www.securityfocus.com/bid/23823 https://exchange.xforce.ibmcloud.com/vulnerabilities/34080 •

CVSS: 7.5EPSS: 2%CPEs: 1EXPL: 1

Buffer overflow in WinAce 2.6.0.5, and possibly earlier versions, allows remote attackers to execute arbitrary code via a temporary (.tmp) file that contains an entry with a long file name. • https://www.exploit-db.com/exploits/1168 http://marc.info/?l=bugtraq&m=112447630109392&w=2 https://exchange.xforce.ibmcloud.com/vulnerabilities/21941 •