CVE-2007-6593
Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain Types in a Lotus 1-2-3 (.123) file in the Worksheet File (WKS) format, as demonstrated by a file with a crafted SRANGE record, a different vulnerability than CVE-2007-5909.
- Affected products
- Autonomy Keyview Sdk, Ibm Lotus Notes
- Ibm Lotus Notes
- = 5.0, 6.0, 6.5, 7.0, 8.0
- Fix
- Available
- CVSS 2.0
- 8.8 HIGH
- EPSS
- 6.3% (93th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2007-12-28
CVE-2007-6593 at NVD
5 known exploits for CVE-2007-6593
Proof-of-concept code and exploit modules indexed by Sploitus