Vulnerability CVE-2011-1218


Published: 2011-05-31   Modified: 2012-02-13

Description:
Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, aka SPR PRAD8E3NSP. NOTE: some of these details are obtained from third party information.

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

Vendor: IBM
Product: Lotus notes 
Version:
8.5.2.2
8.5.2.1
8.5.2.0
8.5.1.5
8.5.1.4
8.5.1.3
8.5.1.2
8.5.1.1
8.5.1.0
8.5.1
8.5.0.1
8.5.0.0
8.5
8.0.2.6
8.0.2.5
8.0.2.4
8.0.2.3
8.0.2.2
8.0.2.1
8.0.2.0
8.0.2
8.0.1
8.0.0
8.0
7.0.4.2
7.0.4.1
7.0.4.0
7.0.4
7.0.3.1
7.0.3
7.0.2.3
7.0.2.2
7.0.2.1
7.0.2
7.0.1.1
7.0.1
7.0.0
7.0
6.5.6.3
6.5.6.2
6.5.6.1
6.5.6
6.5.5.3
6.5.5.2
6.5.5.1
6.5.5
6.5.4.3
6.5.4.2
6.5.4.1
6.5.4
6.5.3.1
6.5.3
6.5.2
6.5.1
6.5
6.0.5
6.0.4
6.0.3
6.0.2.2
6.0.2
6.0.1
6.0
5.0a
5.02
5.0.9a
5.0.9
5.0.8
5.0.7a
5.0.7
5.0.6a.01
5.0.6a
5.0.6
5.0.5.02
5.0.5.01
5.0.5
5.0.4a
5.0.4
5.0.3
5.0.2c
5.0.2b
5.0.2a
5.0.2
5.0.1c
5.0.1b
5.0.1a
5.0.12
5.0.11
5.0.10
5.0.1.02
5.0.1
5.0
4.6.7h
4.6.7a
4.6
4.5
4.2.2
4.2.1
4.2
3.0.0.2
3.0.0.1
See more versions on NVD

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://xforce.iss.net/xforce/xfdb/67625
http://www.securityfocus.com/bid/47962
http://www.ibm.com/support/docview.wss?uid=swg21500034
http://secunia.com/advisories/44624
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14238

Related CVE
CVE-2019-4265
IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160198.
CVE-2019-4558
A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4.2.3.17 that could allow a local attacker to obtain root privilege by injecting parameters into setui...
CVE-2019-4512
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.
CVE-2019-4564
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...
CVE-2019-4514
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 165136.
CVE-2019-4227
IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unauthorized user to conduct a session fixation attack due to clients not being disconnected as they should. IBM X-Force ID: 159352.
CVE-2019-4441
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.
CVE-2019-4422
IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated user to change the accessmgr password. IBM X-Force ID: 162768.

Copyright 2019, cxsecurity.com

 

Back to Top