VulnerabilityModified
CVE-2005-1393
Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.
MEDIUM 4.6EPSS 0.64%
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Affected
- esri/arcinfo workstation
- Source
- cve@mitre.org
References
- http://marc.info/?l=full-disclosure&m=111489411524630&w=2
- http://secunia.com/advisories/15196
- http://securitytracker.com/id?1013852
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=14&MetaID=1015
- http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txtExploit, Patch
- http://marc.info/?l=full-disclosure&m=111489411524630&w=2
- http://secunia.com/advisories/15196
- http://securitytracker.com/id?1013852
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=14&MetaID=1015
- http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txtExploit, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.