7.8
CVE-2007-3168
- EPSS 6.31%
- Veröffentlicht 11.06.2007 22:30:00
- Zuletzt bearbeitet 16.06.2026 22:41:12
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files via the DeleteLocalFile method.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Edraw ≫ Office Viewer Component Version <= 5.0
Edraw ≫ Office Viewer Component Version4.0.5.20
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.31% | 0.927 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 8.6 | 7.8 |
AV:N/AC:M/Au:N/C:N/I:P/A:C
|
http://moaxb.blogspot.com/2007/05/moaxb-28-edraw-office-viewer-component.html
http://osvdb.org/36044
http://secunia.com/advisories/25418
http://shinnai.altervista.org/viewtopic.php?id=42&t_id=31
http://www.ocxt.com/archives/28
http://www.securityfocus.com/bid/24230
http://www.vupen.com/english/advisories/2007/1992
https://exchange.xforce.ibmcloud.com/vulnerabilities/34588
https://www.exploit-db.com/exploits/4010