9.3

CVE-2007-3829

Multiple stack-based buffer overflows in (a) InterActual Player 2.60.12.0717 and (b) Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via a (1) long FailURL attribute in the IAMCE ActiveX Control (IAMCE.dll) or a (2) long URLCode attribute in the IAKey ActiveX Control (IAKey.dll).  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RoxioCineplayer Version3.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.18% 0.941
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/37717
http://osvdb.org/37718
http://secunia.com/advisories/25718
Vendor Advisory
http://secunia.com/advisories/25739
Vendor Advisory
http://www.kb.cert.org/vuls/id/470913
US Government Resource
http://www.kb.cert.org/vuls/id/916897
US Government Resource
http://www.securityfocus.com/bid/24919
https://exchange.xforce.ibmcloud.com/vulnerabilities/35422
https://exchange.xforce.ibmcloud.com/vulnerabilities/35423