Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size for (1) EM_GET_CE_PARAMETER and (2) EM_SET_CE_PARAMETER messages, which leads to a buffer overflow (probably an over-read).
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:11
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/20378 - | |
References | () http://securitytracker.com/id?1016184 - | |
References | () http://www.kb.cert.org/vuls/id/227929 - US Government Resource | |
References | () http://www.kb.cert.org/vuls/id/873409 - US Government Resource | |
References | () http://www.kb.cert.org/vuls/id/WDON-6QAK6D - | |
References | () http://www.vupen.com/english/advisories/2006/2069 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/26745 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/26778 - |
Information
Published : 2006-05-31 22:02
Updated : 2024-11-21 00:11
NVD link : CVE-2006-2708
Mitre link : CVE-2006-2708
CVE.ORG link : CVE-2006-2708
JSON object : View
Products Affected
secure_elements
- class_5_enterprise_vulnerability_management
CWE