9.3

CVE-2007-2758

Multiple buffer overflows in WinImage 8.0.8000 allow user-assisted remote attackers to execute arbitrary code via a FAT image that contains long directory names in a deeply nested directory structure, which triggers (1) a stack-based buffer overflow during extraction, or (2) a heap-based buffer overflow during traversal.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WinimageWinimage Version8.0.8000
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.72% 0.921
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/36081
http://osvdb.org/36082
http://secunia.com/advisories/25277
Vendor Advisory
http://vuln.sg/winimage808000-en.html
http://www.securityfocus.com/bid/24026
http://www.vupen.com/english/advisories/2007/1854
https://exchange.xforce.ibmcloud.com/vulnerabilities/34359
https://exchange.xforce.ibmcloud.com/vulnerabilities/34360