SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-3955

Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a long second argument (varBrowser argument) to the search method.

MEDIUM 6.8EPSS 8.24%

Does this matter?

Lower severity and a low EPSS score (8.24%). Track it; it rarely justifies an emergency change on its own.

Description

Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a long second argument (varBrowser argument) to the search method. NOTE: some of these details are obtained from third party information.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
8.24% probability · 95th percentile
CISA KEV
Not listed
Affected
linkedin/toolbar
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.