CVE-2005-1009
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 57%
from disclosure to weapon0 days
Published on NVDApr 8
1st PoCApr 1
metasploitApr 1
exploitation probability
57%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length that leads to a heap-based buffer overflow, or (2) local users to execute arbitrary code via a long Name entry in the configure.cfg file.
Affected products
n/a · n/apublic PoCs found — 4
exploitdbwww.exploit-db.com/exploits/905unverifiedexploitdbwww.exploit-db.com/exploits/16448unverifiedexploitdbwww.exploit-db.com/exploits/990unverifiedexploitdbwww.exploit-db.com/exploits/906unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://secunia.com/advisories/14814http://securitytracker.com/id?1013625https://exchange.xforce.ibmcloud.com/vulnerabilities/19932http://www.class101.org/netv-locsbof.pdfhttp://www.class101.org/netv-remhbof.pdfhttp://www.hat-squad.com/en/000164.htmlhttp://www.hat-squad.com/en/000165.htmlhttp://www.securityfocus.com/archive/1/394801http://www.securityfocus.com/bid/12967