| Vulnerability Name: | CVE-2007-2514 (CCN-34723) | ||||||||
| Assigned: | 2007-06-04 | ||||||||
| Published: | 2007-06-04 | ||||||||
| Updated: | 2018-10-16 | ||||||||
| Summary: | Stack-based buffer overflow in XferWan.exe as used in multiple products including (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0, and (3) Centennial UK Ltd Discovery 2006 Feature Pack, allows remote attackers to execute arbitrary code via a long request. Note: this might be a reservation duplicate of CVE-2007-1173. "This issue only affects systems running non-secure communications, which comprise a very small percentage of installations worldwide." | ||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2007-2514 Source: CCN Type: TPTI-07-10 Centennial Software XFERWAN Stack Overflow Vulnerability Source: MISC Type: Patch http://dvlabs.tippingpoint.com/advisory/TPTI-07-10 Source: OSVDB Type: UNKNOWN 42059 Source: SREASON Type: UNKNOWN 2785 Source: CCN Type: SECTRACK ID: 1018191 Centennial Discovery Stack Overflow in `XferWan.exe` Lets Remote Users Execute Arbitrary Code Source: CCN Type: Centennial Software Web site Centennial Software | News Source: CCN Type: OSVDB ID: 42059 Centennial Software XferWan.exe Request Handling Overflow Source: BUGTRAQ Type: UNKNOWN 20070605 TPTI-07-10: Centennial Software XferWan.exe Stack Overflow Vulnerability Source: BID Type: Patch 24317 Source: CCN Type: BID-24317 Multiple Vendor XFERWAN.EXE Filename Remote Buffer Overflow Vulnerability Source: SECTRACK Type: UNKNOWN 1018191 Source: CCN Type: Symantec Web site Symantec Discovery Source: XF Type: UNKNOWN centennial-xferwan-bo(34723) Source: XF Type: UNKNOWN centennial-xferwan-bo(34723) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||