CVE-2007-2918
Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 34.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow remote attackers to cause a denial of service (browser crash) and execute arbitrary code via unspecified vectors.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 34.06% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- logitech/videocall
- Source
- cret@cert.org
References
- http://osvdb.org/36820
- http://osvdb.org/36821
- http://osvdb.org/36822
- http://osvdb.org/36823
- http://osvdb.org/36824
- http://secunia.com/advisories/25514
- http://www.kb.cert.org/vuls/id/330289US Government Resource
- http://www.securityfocus.com/bid/24254
- http://www.vupen.com/english/advisories/2007/2018
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34658
- http://osvdb.org/36820
- http://osvdb.org/36821
- http://osvdb.org/36822
- http://osvdb.org/36823
- http://osvdb.org/36824
- http://secunia.com/advisories/25514
- http://www.kb.cert.org/vuls/id/330289US Government Resource
- http://www.securityfocus.com/bid/24254
- http://www.vupen.com/english/advisories/2007/2018
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34658
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.