7 results (0.011 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 2

Integer overflow in unace 1.2b allows remote attackers to cause a denial of service (crash) via a small file header in an ace archive, which triggers a buffer overflow. Desbordamiento de enteros en unace 1.2b permite a atacantes remotos causar una denegación de servicio (caída) a través de una cabecera de fichero pequeña en un archivo ace, lo que provoca un desbordamiento de buffer. • http://www.debian.org/security/2015/dsa-3178 http://www.openwall.com/lists/oss-security/2015/02/24/1 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775003 • CWE-189: Numeric Errors •

CVSS: 10.0EPSS: 30%CPEs: 1EXPL: 0

Heap-based buffer overflow in WinAce 2.65 and earlier, and possibly other versions before 2.69, allows user-assisted remote attackers to execute arbitrary code via a long filename in a compressed UUE archive. Desbordamiento de búfer basado en montículo en WinAce 2.65 y versiones anteriores, y posiblemente otras versiones anteriores a 2.69, permite a atacantes remotos con la complicidad del usuario ejecutar código de su elección mediante un nombre de fichero largo en un archivo comprimido UUE. • http://jvn.jp/jp/JVN%2344736880/index.html http://jvndb.jvn.jp/contents/ja/2007/JVNDB-2007-000822.html http://osvdb.org/40267 http://secunia.com/advisories/28215 http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20071225 http://www.securityfocus.com/bid/27017 http://www.vupen.com/english/advisories/2007/4312 https://exchange.xforce.ibmcloud.com/vulnerabilities/39268 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.8EPSS: 7%CPEs: 59EXPL: 1

unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. El archivo unzoo.c, tal como se utiliza en varios productos, incluyendo AMaViS versión 2.4.1 y anteriores, permite a los atacantes remotos causar una denegación de servicio (bucle infinito) por medio de un archivo ZOO con una estructura direntry que apunta hacia un archivo anterior. • http://osvdb.org/36208 http://secunia.com/advisories/25315 http://securityreason.com/securityalert/2680 http://www.amavis.org/security/asa-2007-2.txt http://www.securityfocus.com/archive/1/467646/100/0/threaded http://www.securityfocus.com/bid/23823 https://exchange.xforce.ibmcloud.com/vulnerabilities/34080 • CWE-399: Resource Management Errors •

CVSS: 7.8EPSS: 1%CPEs: 3EXPL: 1

WinAce allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. WinAce permite a atacantes remotos provocar una denegación de servicio (bucle infinito) mediante un archivo ZOO con una estructura de entrada de directorio (direntry structure) que apunta a un fichero anterior. • http://osvdb.org/41750 http://securityreason.com/securityalert/2680 http://www.securityfocus.com/archive/1/467646/100/0/threaded http://www.securityfocus.com/bid/23823 https://exchange.xforce.ibmcloud.com/vulnerabilities/34080 •

CVSS: 5.1EPSS: 1%CPEs: 1EXPL: 0

Heap-based buffer overflow in WinACE 2.60 allows user-assisted attackers to execute arbitrary code via a large header block in an ARJ archive. • http://secunia.com/advisories/17251 http://secunia.com/secunia_research/2005-67/advisory http://securityreason.com/securityalert/479 http://securitytracker.com/id?1015672 http://www.osvdb.org/23383 http://www.securityfocus.com/archive/1/425894/100/0/threaded http://www.securityfocus.com/bid/16786 http://www.vupen.com/english/advisories/2006/0709 https://exchange.xforce.ibmcloud.com/vulnerabilities/24872 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •