HIGH
Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow
Published Mar 5, 2010
10.0
HIGHCVSS 2.0
EPSS 3.74%
Description
Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.
Affected products
No data.
OR
- 8.5
- 8.0
- 8.1.1
- 8.1.1
- 9.0.1
- 9.0.1
- 10.0
- 10.0
- 8.1.1
- 9.0.1
- 10.0
- n/a
- 5.0.0
- 5.0.1.181
- 5.0.1.182
- 5.0.1.189
- 5.0.11
- 5.0.12
- 5.0.13
- 6.0.6
- 6.0.7
- 6.0.8
- 7.5.3.25
- 7.5.4.29
- 7.5.5.32
- 7.5.6
- 7.5.7
- 7.5.8
- 8.0
- 8.0.1
- 8.0.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=858 third-party-advisoryx_refsource_IDEFENSEExploit
- http://www-01.ibm.com/support/docview.wss?uid=swg21440812 x_refsource_CONFIRM
- http://www.securityfocus.com/bid/38468 vdb-entryx_refsource_BID
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100304_00 x_refsource_CONFIRM
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-3016 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=858 | third-party-advisoryx_refsource_IDEFENSEExploit | |
| http://www-01.ibm.com/support/docview.wss?uid=swg21440812 | x_refsource_CONFIRM | |
| http://www.securityfocus.com/bid/38468 | vdb-entryx_refsource_BID | |
| http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100304_00 | x_refsource_CONFIRM | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-3016 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 5, 2010
Updated Aug 7, 2024
Reserved Aug 31, 2009
Link CVE-2009-3032
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-3016 Assigner mitre
Published Mar 5, 2010
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-3016