9.3
CVE-2007-4470
- EPSS 6.63%
- Veröffentlicht 10.09.2007 17:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:09
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
Multiple stack-based buffer overflows in the Earth Resource Mapping NCSView ActiveX control before 3.4.0.242 in NCSView.dll, as distributed in ER Mapper ECW JPEG 2000 Plug-in before 8.1, allow remote attackers to execute arbitrary code via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Er Mapper ≫ Image Web Server Ecw Jpeg 2000 Plug-in Version <= 8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.63% | 0.93 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://osvdb.org/37780
http://secunia.com/advisories/26729
http://www.kb.cert.org/vuls/id/589188
http://www.securityfocus.com/bid/25584
http://www.vupen.com/english/advisories/2007/3093
https://exchange.xforce.ibmcloud.com/vulnerabilities/36497