CVE-2005-3922

UnknownEPSS 5.55%

Last modified

CVE-2005-3922 is a vulnerability of currently unknown severity. Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive.. EPSS estimates a 5.55% chance of exploitation in the next 30 days.

Description

Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive.

Metrics

EPSS Probability
5.55%

91.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
PandaPanda Activescan5.0
PandaPanda Antivirus2.0
PandaPanda Antivirus Platinum2.0
PandaPanda Businessecure AntivirusAll versions
PandaPanda Clientshield With Truprevent TechnologiesAll versions
PandaPanda Enterprisecure With Truprevent TechnologiesAll versions
PandaPanda ExchangesecureAll versions
PandaPanda FilesecureAll versions
PandaPanda Filesecure With Truprevent TechnologiesAll versions
PandaPanda GatedefenderAll versions
PandaPanda Isa SecureAll versions
PandaPanda Panda Enterprisecure AntivirusAll versions
PandaPanda Platinum 2006 Internet SecurityAll versions
PandaPanda Security3.0
PandaPanda TitaniumAll versions
PandaPanda Titanium 2005 AntivirusAll versions
PandaPanda Titanium 2006 Antivirus \+ AntispywareAll versions
PandaPanda Truprevent Personal2005
PandaPanda Truprevent Personal2006
PandaPanda WebadminAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2005-3922?
Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive.
How severe is CVE-2005-3922?
Severity scoring for CVE-2005-3922 is pending analysis. The EPSS model estimates a 5.55% probability of exploitation in the next 30 days.
How do I fix CVE-2005-3922?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2005-3922?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST