CVE-2007-5405

CWE-119Buffer Overflow3 documents3 sources
Severity
9.3CRITICAL
EPSS
34.7%
top 2.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateMay 1

Description

Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a .ag file with (1) a long ENCODING attribute in a *BEGIN tag, (2) a long token, or (3) the initial *BEGIN tag.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages5 packages

NVDsymantec/mail_security4 versions+3
NVDibm/lotus_notes5 versions+4
NVDautonomy/keyview10.3.0.0, 2.0.0.2+1
NVDactivepdf/docconverter3.8.2_.5, 3.8.4.0+1

🔴Vulnerability Details

2
GHSA
GHSA-h466-38fm-2cfq: Multiple buffer overflows in kpagrdr2022-05-01
CVEList
CVE-2007-5405: Multiple buffer overflows in kpagrdr2008-04-10
CVE-2007-5405 (CRITICAL CVSS 9.3) | Multiple buffer overflows in kpagrd | cvebase.io