// For flags

CVE-2005-2384

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory traversal vulnerability in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to write arbitrary files via an ACE archive containing filenames with (1) .. or (2) absolute pathnames.

Vulnerabilidad de franqueo de directorios en librería de compresión (UNACEV2.DLL), usada en avast! Antivirus Home/Professional Edition 4.6.665 y Server Edition 4.6.460 permite que atacantes remotos escriban ficheros arbitrarios mediante un archivo ACE que contiene nombre de ficheros con 1) .. o 2) paths absolutos.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2005-07-27 CVE Reserved
  • 2005-07-27 CVE Published
  • 2024-07-03 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Alwil
Search vendor "Alwil"
Avast Antivirus
Search vendor "Alwil" for product "Avast Antivirus"
4.6.460
Search vendor "Alwil" for product "Avast Antivirus" and version "4.6.460"
server
Affected
Alwil
Search vendor "Alwil"
Avast Antivirus
Search vendor "Alwil" for product "Avast Antivirus"
4.6.665
Search vendor "Alwil" for product "Avast Antivirus" and version "4.6.665"
home
Affected
Alwil
Search vendor "Alwil"
Avast Antivirus
Search vendor "Alwil" for product "Avast Antivirus"
4.6.665
Search vendor "Alwil" for product "Avast Antivirus" and version "4.6.665"
pro
Affected