VulnerabilityModified
CVE-2007-2984
Multiple stack-based buffer overflows in the Media Technology Group CDPass ActiveX control in CDPass.dll allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the GetTOC2 method.
MEDIUM 6.8EPSS 3.45%
Does this matter?
Lower severity and a low EPSS score (3.45%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple stack-based buffer overflows in the Media Technology Group CDPass ActiveX control in CDPass.dll allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the GetTOC2 method.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.45% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- media technology group/cdpass activex control
- Source
- cve@mitre.org
References
- http://osvdb.org/36717
- http://secunia.com/advisories/25471Vendor Advisory
- http://www.kb.cert.org/vuls/id/933353Patch, US Government Resource
- http://www.securityfocus.com/bid/24220
- http://www.vupen.com/english/advisories/2007/1978Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34578
- http://osvdb.org/36717
- http://secunia.com/advisories/25471Vendor Advisory
- http://www.kb.cert.org/vuls/id/933353Patch, US Government Resource
- http://www.securityfocus.com/bid/24220
- http://www.vupen.com/english/advisories/2007/1978Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34578
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.