8.5

CVE-2007-3901

Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted SAMI file.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftDirectx Version5.2
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version6.1
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version7.0
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version7.0a
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version7.1
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version8.0
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version8.0a
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version8.1
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version8.1a
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version8.1b
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version8.2
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version9.0a
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version9.0b
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version9.0c
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
MicrosoftDirectx Version10.0
   MicrosoftWindows 2000
   MicrosoftWindows 2003 Server Versiondatacenter_edition
   MicrosoftWindows 2003 Server Versionenterprise_edition
   MicrosoftWindows 2003 Server Versionstandard
   MicrosoftWindows 2003 Server Versionweb_edition
   MicrosoftWindows Vista
   MicrosoftWindows Xp Editionhome
   MicrosoftWindows Xp Editionprofessional
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 78.53% 0.99
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.