Vulnerability Details CVE-2006-0994
Multiple Sophos Anti-Virus products, including Anti-Virus for Windows 5.x before 5.2.1 and 4.x before 4.05, when cabinet file inspection is enabled, allows remote attackers to execute arbitrary code via a CAB file with "invalid folder count values," which leads to heap corruption.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.427
EPSS Ranking 97.3%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2006-0994
-
cpe:2.3:a:sophos:sophos_anti-virus:4.02
-
cpe:2.3:a:sophos:sophos_anti-virus:4.04
-
cpe:2.3:a:sophos:sophos_anti-virus:5.0.0
-
cpe:2.3:a:sophos:sophos_anti-virus:5.0.1
-
cpe:2.3:a:sophos:sophos_anti-virus:5.0.2
-
cpe:2.3:a:sophos:sophos_anti-virus:5.0.4
-
cpe:2.3:a:sophos:sophos_anti-virus:5.1
-
cpe:2.3:a:sophos:sophos_anti-virus:5.1.3
-
cpe:2.3:a:sophos:sophos_anti-virus:5.1.4
-
cpe:2.3:a:sophos:sophos_anti-virus:5.2.0