CVE-2007-4467
Multiple stack-based buffer overflows in the Oracle JInitiator ActiveX control (beans.ocx) 1.1.8.16 and earlier, as used by Oracle Forms applications from Oracle and third parties, allow remote attackers to execute arbitrary code via unspecified…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple stack-based buffer overflows in the Oracle JInitiator ActiveX control (beans.ocx) 1.1.8.16 and earlier, as used by Oracle Forms applications from Oracle and third parties, allow remote attackers to execute arbitrary code via unspecified "initialization parameters." NOTE: it was later reported that 1.1.8.3 through 1.1.8.25, and probably 1.1.5.x and 1.1.7.x, are affected.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 21.07% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- oracle/jinitiator
- Source
- cret@cert.org
References
- http://osvdb.org/37711
- http://secunia.com/advisories/26644Vendor Advisory
- http://securitytracker.com/id?1018618
- http://www.integrigy.com/security-resources/analysis/integrigy-oracle-jinitiator-vulnerability.pdf
- http://www.kb.cert.org/vuls/id/474433US Government Resource
- http://www.securityfocus.com/archive/1/479186/100/100/threaded
- http://www.securityfocus.com/bid/25473
- http://www.vupen.com/english/advisories/2007/3007Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36310
- http://osvdb.org/37711
- http://secunia.com/advisories/26644Vendor Advisory
- http://securitytracker.com/id?1018618
- http://www.integrigy.com/security-resources/analysis/integrigy-oracle-jinitiator-vulnerability.pdf
- http://www.kb.cert.org/vuls/id/474433US Government Resource
- http://www.securityfocus.com/archive/1/479186/100/100/threaded
- http://www.securityfocus.com/bid/25473
- http://www.vupen.com/english/advisories/2007/3007Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36310
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.