7.5
CVE-2007-0803
- EPSS 5.81%
- Veröffentlicht 07.02.2007 11:28:00
- Zuletzt bearbeitet 16.06.2026 22:36:19
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple buffer overflows in STLport before 5.0.3 allow remote attackers to execute arbitrary code via unspecified vectors relating to (1) "print floats" and (2) a missing null termination in the "rope constructor."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Stlport Project ≫ Stlport Version < 5.0.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.81% | 0.922 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
http://osvdb.org/33106
http://osvdb.org/33107
http://secunia.com/advisories/24024
http://secunia.com/advisories/24428
http://security.gentoo.org/glsa/glsa-200703-07.xml
http://sourceforge.net/project/shownotes.php?release_id=483468
http://www.securityfocus.com/bid/22423
http://www.vupen.com/english/advisories/2007/0498
https://exchange.xforce.ibmcloud.com/vulnerabilities/32242
https://exchange.xforce.ibmcloud.com/vulnerabilities/32244