CVE-2007-5436
Buffer overflow in a certain ActiveX control in ScanObjectBrowser.DLL in G DATA Antivirus 2007 might allow remote attackers to execute arbitrary code via unspecified parameters to the SelectPath function.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in a certain ActiveX control in ScanObjectBrowser.DLL in G DATA Antivirus 2007 might allow remote attackers to execute arbitrary code via unspecified parameters to the SelectPath function. NOTE: this issue might not cross privilege boundaries in most environments, since it is not marked as safe for scripting.
- CVSS 2.0
- 7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 4.95% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- gdata/antivirus
- Source
- cve@mitre.org
References
- http://osvdb.org/42476
- http://securityreason.com/securityalert/3219
- http://www.eleytt.com/advisories/eleytt_GDATA2007_1.pdfVendor Advisory
- http://www.securityfocus.com/archive/1/482021/100/0/threaded
- http://www.securityfocus.com/bid/26008
- http://osvdb.org/42476
- http://securityreason.com/securityalert/3219
- http://www.eleytt.com/advisories/eleytt_GDATA2007_1.pdfVendor Advisory
- http://www.securityfocus.com/archive/1/482021/100/0/threaded
- http://www.securityfocus.com/bid/26008
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.