« Volver al listado

CVE-2006-5967

Estado: ModificadaMedia (5.1)—

Race condition in Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to cause memory corruption and execute arbitrary code via unknown vectors related to multiple invocations of the Analizar method in the ActiveScan.1 ActiveX control, which is not thread safe.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-5967",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT-CNA@flexerasoftware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-11-17T22:07:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/21763",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/secunia_research/2006-64/advisory/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/451864/100/0/threaded",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/21132",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4536",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30319",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/advisories/21763",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/secunia_research/2006-64/advisory/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/451864/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/21132",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4536",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30319",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Race condition in Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to cause memory corruption and execute arbitrary code via unknown vectors related to multiple invocations of the Analizar method in the ActiveScan.1 ActiveX control, which is not thread safe."
    },
    {
      "lang": "es",
      "value": "Condición de carrera en Panda ActiveScan 5.53.00, y otras versiones anteriores a 5.54.01, permiten a un atacante remoto provocar corrupción de memoria y ejecutar código de su elección a través de vectores desconocidos relacionados con múltiples invocaciones del método Analizar en el controlador ActiveX de ActiveScan.1, el cual no es un hilo seguro."
    }
  ],
  "lastModified": "2026-06-16T22:32:13.557",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:panda:activescan:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5AE78593-0DC5-47C1-9624-5E304A7215B9"
            },
            {
              "criteria": "cpe:2.3:a:panda:activescan:5.53.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA17277C-337F-4AE0-B92B-C572EEFCAF83"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "PSIRT-CNA@flexerasoftware.com",
  "evaluatorSolution": "This vulnerability is addressed in the following product release:\r\nPanda, ActiveScan, 5.54.01"
}