VulnerabilityModified
CVE-2007-3491
Buffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attackers to have an unknown impact via a malformed TCP/IP message.
HIGH 7.5EPSS 2.52%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attackers to have an unknown impact via a malformed TCP/IP message.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.52% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- progress/openedge
- Source
- cve@mitre.org
References
- http://osvdb.org/37747
- http://secunia.com/advisories/25865
- http://securityreason.com/securityalert/2851
- http://www.psdn.com/library/servlet/KbServlet/download/2629-102-4821/README_101B_01.pdf
- http://www.securityfocus.com/archive/1/472349/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35104
- http://osvdb.org/37747
- http://secunia.com/advisories/25865
- http://securityreason.com/securityalert/2851
- http://www.psdn.com/library/servlet/KbServlet/download/2629-102-4821/README_101B_01.pdf
- http://www.securityfocus.com/archive/1/472349/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35104
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.