CVE-2007-5257
Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 15.22% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- edraw/office viewer component
- Source
- cve@mitre.org
References
- http://osvdb.org/37724
- http://secunia.com/advisories/27017Vendor Advisory
- http://shinnai.altervista.org/exploits/txt/TXT_O5FvsIzILBHQr7QbK2kD.htmlExploit
- http://www.securityfocus.com/bid/25892Exploit
- http://www.vupen.com/english/advisories/2007/3329
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36879
- https://www.exploit-db.com/exploits/4474
- http://osvdb.org/37724
- http://secunia.com/advisories/27017Vendor Advisory
- http://shinnai.altervista.org/exploits/txt/TXT_O5FvsIzILBHQr7QbK2kD.htmlExploit
- http://www.securityfocus.com/bid/25892Exploit
- http://www.vupen.com/english/advisories/2007/3329
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36879
- https://www.exploit-db.com/exploits/4474
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.