HIGH · 9.3

CVE-2007-5405

Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF Doc...

Vulnerability Description

Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a .ag file with (1) a long ENCODING attribute in a *BEGIN tag, (2) a long token, or (3) the initial *BEGIN tag.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
ActivepdfDocconverter3.8.2_.5
AutonomyKeyview2.0.0.2
IbmLotus Notes6.0
SymantecMail Security5.0
SymantecMail Security Appliance5.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-5405?

CVE-2007-5405 is a vulnerability with a CVSS score of 9.3 (HIGH). Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF Doc...

How severe is CVE-2007-5405?

CVE-2007-5405 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-5405?

Check the references section above for vendor advisories and patch information. Affected products include: Activepdf Docconverter, Autonomy Keyview, Ibm Lotus Notes, Symantec Mail Security, Symantec Mail Security Appliance.