7.5

CVE-2007-0174

Exploit
Multiple stack-based multiple buffer overflows in the BRWOSSRE2UC.dll ActiveX Control in Sina UC2006 and earlier allow remote attackers to execute arbitrary code via a long string in the (1) astrVerion parameter to the SendChatRoomOpt function or (2) the astrDownDir parameter to the SendDownLoadFile function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SinaSina Versionuc2006
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.92% 0.91
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=full-disclosure&m=116832852700467&w=2
http://osvdb.org/32659
http://secunia.com/advisories/23638
Vendor Advisory
http://secway.org/advisory/ad20070109EN.txt
Vendor Advisory
Exploit
http://www.securityfocus.com/archive/1/456378/100/0/threaded
http://www.securityfocus.com/bid/21958
http://www.vupen.com/english/advisories/2007/0093
https://exchange.xforce.ibmcloud.com/vulnerabilities/31348
https://exchange.xforce.ibmcloud.com/vulnerabilities/31350