« Volver al listado

CVE-2006-5937

Estado: ModificadaAlta (7.5)—

Multiple integer overflows in Grisoft AVG Anti-Virus before 7.1.407 allow remote attackers to execute arbitrary code via crafted (1) CAB or (2) RAR archives that trigger a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-5937",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-11-16T00:07:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=full-disclosure&m=116343152030074&w=2",
      "tags": [
        "Mailing List"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/22811",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.grisoft.com/doc/36365/lng/us/tpl/tpl01",
      "tags": [
        "Patch",
        "Product"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4498",
      "tags": [
        "Not Applicable"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=full-disclosure&m=116343152030074&w=2",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/22811",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.grisoft.com/doc/36365/lng/us/tpl/tpl01",
      "tags": [
        "Patch",
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4498",
      "tags": [
        "Not Applicable"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple integer overflows in Grisoft AVG Anti-Virus before 7.1.407 allow remote attackers to execute arbitrary code via crafted (1) CAB or (2) RAR archives that trigger a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information."
    },
    {
      "lang": "es",
      "value": "Múltiples desbordamientos de búfer en  Grisoft AVG Anti-Virus anterior a 7.1.407 permite a un atacante remoto ejecutar código a través de archivos (1)CAB o (2)RAR manipulados que disparan un desbordamiento de búfer basado en pila. NOTA: algunos de estos detalles se obtuvieron de información de terceros."
    }
  ],
  "lastModified": "2026-06-16T22:32:10.393",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:grisoft:avg_antivirus:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9876E4EA-9C93-4B3F-8E49-C34BB3CF5A5B"
            },
            {
              "criteria": "cpe:2.3:a:grisoft:avg_antivirus:7.0.251:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A2AD8F3-96E4-4F2F-87A2-786EE0672930"
            },
            {
              "criteria": "cpe:2.3:a:grisoft:avg_antivirus:7.0.323:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5188CBC-298E-4F5A-A817-2DB05B178D85"
            },
            {
              "criteria": "cpe:2.3:a:grisoft:avg_antivirus:7.1.308:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A38FC89B-5846-4693-A589-02C27E50A7F3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}