CVE-2007-3955
Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a long second argument (varBrowser argument) to the search method.
Does this matter?
Lower severity and a low EPSS score (8.24%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a long second argument (varBrowser argument) to the search method. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 8.24% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- linkedin/toolbar
- Source
- cve@mitre.org
References
- http://osvdb.org/37696
- http://secunia.com/advisories/26181Vendor Advisory
- http://www.securityfocus.com/bid/25032Exploit
- http://www.vdalabs.com/tools/linkedin.html
- http://www.vupen.com/english/advisories/2007/2620
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35578
- https://www.exploit-db.com/exploits/4217
- http://osvdb.org/37696
- http://secunia.com/advisories/26181Vendor Advisory
- http://www.securityfocus.com/bid/25032Exploit
- http://www.vdalabs.com/tools/linkedin.html
- http://www.vupen.com/english/advisories/2007/2620
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35578
- https://www.exploit-db.com/exploits/4217
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.