[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-2120Date: (C)2005-10-13   (M)2023-12-22


Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.5
Exploit Score: 8.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1015042
BID-15065
SECUNIA-17166
SECUNIA-17172
SECUNIA-17223
OSVDB-18830
SREASON-71
AD20051011c
MS05-047
TA05-284A
VU#214572
http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf
oval:org.mitre.oval:def:1244
oval:org.mitre.oval:def:1328
oval:org.mitre.oval:def:1519

CPE    2
cpe:/o:microsoft:windows_xp::sp1:tablet_pc
cpe:/o:microsoft:windows_xp::sp2:tablet_pc
OVAL    3
oval:org.mitre.oval:def:1328
oval:org.mitre.oval:def:1519
oval:org.mitre.oval:def:1244

© SecPod Technologies