7.5

CVE-2007-4816

Exploit
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown impact via a long (1) URL, (2) backImage, or (3) titleImage property value; (4) a long first argument to the advancedOpen method; a long argument to the (5) isDVDPath or (6) rawParse method; or (7) a .smpl file with a long path attribute in an item element in a PlayList.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BaofengStorm Version2.8
BaofengStorm Version2.9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.08% 0.946
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://osvdb.org/40491
http://secunia.com/advisories/26749
http://www.milw0rm.com/sploits/09082007-storm.zip
Exploit
http://www.securityfocus.com/bid/25601
Exploit
http://www.vupen.com/english/advisories/2007/3111
https://exchange.xforce.ibmcloud.com/vulnerabilities/36540
https://exchange.xforce.ibmcloud.com/vulnerabilities/36542
https://exchange.xforce.ibmcloud.com/vulnerabilities/36543
https://www.exploit-db.com/exploits/4375