← All CVEs

CVE-2006-5647

medium · 6.4

Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name length memory consumption vulnerability."

6.4
CVSS
20.7%
EPSS (exploit prob.)
97th
EPSS percentile
2006-11-01
Published

AV:N/AC:L/Au:N/C:N/I:P/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
sophosanti-virus4.04
sophosanti-virus4.05
sophosanti-virus4.5.3
sophosanti-virus4.5.4
sophosanti-virus4.5.11
sophosanti-virus4.5.12
sophosanti-virus4.7.1
sophosanti-virus4.7.2
sophosanti-virus5.0.1
sophosanti-virus5.0.2
sophosanti-virus5.0.4
sophosanti-virus5.1
sophosanti-virus5.2
sophosanti-virus5.2.1
sophosanti-virus6.0.4
sophosendpoint_security<= 6.04

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-5647