CVE-2010-1525
Estado: ModificadaAlta (9.3)—
Integer underflow in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted size for an unspecified record type, which triggers a heap-based buffer overflow.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.97%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-189
Referencias
- http://secunia.com/secunia_research/2010-49/
- http://www-01.ibm.com/support/docview.wss?uid=swg21440812
- http://www.securityfocus.com/bid/41928
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100727_01
- http://secunia.com/secunia_research/2010-49/
- http://www-01.ibm.com/support/docview.wss?uid=swg21440812
- http://www.securityfocus.com/bid/41928
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100727_01
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-1525",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "PSIRT-CNA@flexerasoftware.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-08-17T20:00:03.127",
"references": [
{
"url": "http://secunia.com/secunia_research/2010-49/",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21440812",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.securityfocus.com/bid/41928",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100727_01",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://secunia.com/secunia_research/2010-49/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21440812",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/41928",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100727_01",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-189"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Integer underflow in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted size for an unspecified record type, which triggers a heap-based buffer overflow."
},
{
"lang": "es",
"value": "Desbordamiento de entero en el lector SpreadSheet Lotus 123 (wkssr.dll) de Autonomy KeyView v10.4 y v10.9, como el usuado en IBM, Symantec, y otros productos, permite a los atacantes remotos causar una denegación de servicio (caída) y posiblemente ejecutar código a su elección a través de tamaños manipulados para un tipo de registro no especificado, lo que dispara un desbordamiento de búfer basados en pila."
}
],
"lastModified": "2026-06-16T23:18:33.343",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:autonomy:keyview_export_sdk:10.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F588C397-FB3F-4A04-A015-B6F6D9C3B994"
},
{
"criteria": "cpe:2.3:a:autonomy:keyview_export_sdk:10.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C456319D-6699-4970-A146-6E52DD285D7F"
},
{
"criteria": "cpe:2.3:a:autonomy:keyview_filter_sdk:10.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C558D1E3-4C6B-4C00-A415-5B9E343073D8"
},
{
"criteria": "cpe:2.3:a:autonomy:keyview_filter_sdk:10.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "706571F3-D347-4760-A55B-4F465DAFCBFF"
},
{
"criteria": "cpe:2.3:a:autonomy:keyview_viewer_sdk:10.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4056FDC9-27A4-41D9-9C84-B50A66F30161"
},
{
"criteria": "cpe:2.3:a:autonomy:keyview_viewer_sdk:10.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73ECC62B-CED2-4401-A2F7-8E714D20D111"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "PSIRT-CNA@flexerasoftware.com"
}