6.8

CVE-2007-4725

Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute arbitrary code via a long filename in an archive, leading to a heap-based buffer overflow.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
7-zip7-zip Version <= 4.42
7-zip7-zip Version4.43 Updatebeta
7-zip7-zip Version4.44 Updatebeta
7-zip7-zip Version4.45 Updatebeta
7-zip7-zip Version4.46 Updatebeta
7-zip7-zip Version4.47 Updatebeta
7-zip7-zip Version4.48 Updatebeta
7-zip7-zip Version4.49 Updatebeta
7-zip7-zip Version4.50 Updatebeta
7-zip7-zip Version4.51 Updatebeta
7-zip7-zip Version4.52 Updatebeta
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 15.87% 0.945
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.