7.5
CVE-2007-4816
- EPSS 9.08%
- Veröffentlicht 11.09.2007 19:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:50
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown impact via a long (1) URL, (2) backImage, or (3) titleImage property value; (4) a long first argument to the advancedOpen method; a long argument to the (5) isDVDPath or (6) rawParse method; or (7) a .smpl file with a long path attribute in an item element in a PlayList.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.08% | 0.946 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://osvdb.org/40491
http://secunia.com/advisories/26749
http://www.milw0rm.com/sploits/09082007-storm.zip
http://www.securityfocus.com/bid/25601
http://www.vupen.com/english/advisories/2007/3111
https://exchange.xforce.ibmcloud.com/vulnerabilities/36540
https://exchange.xforce.ibmcloud.com/vulnerabilities/36542
https://exchange.xforce.ibmcloud.com/vulnerabilities/36543
https://www.exploit-db.com/exploits/4375