V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2009-3032
CVE
Critical

Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail …

CVSS
10.0
Critical
EPSS
0.04
p88
Published
2009-01-01
Updated
2009-01-01
Description

Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.

Tags · CWE
CWE-189
Affected products
Lotus_notesBrightmail_gatewayData_loss_prevention_detection_serversData_loss_prevention_endpoint_agentsIm_manager_2007Mail_security
CVSS vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Timeline
2009-01-01
Published
2009-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.037 · p88
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
brightmail_gateway*Tracked
data_loss_prevention_detection_servers*Tracked
data_loss_prevention_endpoint_agents*Tracked
im_manager_2007*Tracked
lotus_notes*Tracked
mail_security*Tracked
Source databases
CVE