CVE-2010-0133
Autonomy KeyView wkssr.dll Record Parsing Buffer Overflows
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple stack-based buffer overflows in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allow remote attackers to execute arbitrary code via unspecified vectors related to "certain records."
Múltiples desbordamientos de búfer basados en pila en lector SpreadSheet Lotus 123 (wkssr.dll) de Autonomy KeyView v10.4 y v10.9, como el usado en IBM, Symantec, y otros productos, permite a atacantes remotos ejecutar código a su elección a través de vectores no especificados relacionados con "ciertos registros".
Secunia Research has discovered two vulnerabilities in Autonomy KeyView, which can be exploited by malicious people to compromise a vulnerable system. The vulnerabilities are caused by boundary errors in the SpreadSheet Lotus 123 reader (wkssr.dll) when parsing certain records. This can be exploited to cause stack-based buffer overflows via specially crafted files. Successful exploitation allows execution of arbitrary code. Autonomy KeyView versions 10.4 and 10.9 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-01-04 CVE Reserved
- 2010-07-28 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21440812 | X_refsource_confirm | |
http://www.securityfocus.com/bid/41928 | Vdb Entry | |
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100727_01 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/secunia_research/2010-28 | 2013-02-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Autonomy Search vendor "Autonomy" | Keyview Export Sdk Search vendor "Autonomy" for product "Keyview Export Sdk" | 10.4 Search vendor "Autonomy" for product "Keyview Export Sdk" and version "10.4" | - |
Affected
| ||||||
Autonomy Search vendor "Autonomy" | Keyview Export Sdk Search vendor "Autonomy" for product "Keyview Export Sdk" | 10.9 Search vendor "Autonomy" for product "Keyview Export Sdk" and version "10.9" | - |
Affected
| ||||||
Autonomy Search vendor "Autonomy" | Keyview Filter Sdk Search vendor "Autonomy" for product "Keyview Filter Sdk" | 10.4 Search vendor "Autonomy" for product "Keyview Filter Sdk" and version "10.4" | - |
Affected
| ||||||
Autonomy Search vendor "Autonomy" | Keyview Filter Sdk Search vendor "Autonomy" for product "Keyview Filter Sdk" | 10.9 Search vendor "Autonomy" for product "Keyview Filter Sdk" and version "10.9" | - |
Affected
| ||||||
Autonomy Search vendor "Autonomy" | Keyview Viewer Sdk Search vendor "Autonomy" for product "Keyview Viewer Sdk" | 10.4 Search vendor "Autonomy" for product "Keyview Viewer Sdk" and version "10.4" | - |
Affected
| ||||||
Autonomy Search vendor "Autonomy" | Keyview Viewer Sdk Search vendor "Autonomy" for product "Keyview Viewer Sdk" | 10.9 Search vendor "Autonomy" for product "Keyview Viewer Sdk" and version "10.9" | - |
Affected
|