// For flags

CVE-2005-2385

 

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer overflow in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to execute arbitrary code via an ACE archive containing a long filename.

Desbordamiento de búfer en librería de compresión (UNACEV2.DLL), usada en avast! Antivirus Home/Professional Edition 4.6.665 y Server Edition 4.6.460 permite que atacantes remotos ejecuten código arbitrario mediante un archivo ACE que contenga un nombre de fichero largo.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2005-07-27 CVE Reserved
  • 2005-07-27 CVE Published
  • 2024-07-03 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Alwil
Search vendor "Alwil"
Avast Antivirus
Search vendor "Alwil" for product "Avast Antivirus"
4.6.460
Search vendor "Alwil" for product "Avast Antivirus" and version "4.6.460"
server
Affected
Alwil
Search vendor "Alwil"
Avast Antivirus
Search vendor "Alwil" for product "Avast Antivirus"
4.6.665
Search vendor "Alwil" for product "Avast Antivirus" and version "4.6.665"
home
Affected
Alwil
Search vendor "Alwil"
Avast Antivirus
Search vendor "Alwil" for product "Avast Antivirus"
4.6.665
Search vendor "Alwil" for product "Avast Antivirus" and version "4.6.665"
pro
Affected