« Volver al listado

CVE-2007-3169

Estado: ModificadaAlta (9.3)—

Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long first argument to the HttpDownloadFile method.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-3169",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-06-11T22:30:00.000",
  "references": [
    {
      "url": "http://moaxb.blogspot.com/2007/05/moaxb-29-edraw-office-viewer-component.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/36045",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/25418",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://shinnai.altervista.org/viewtopic.php?id=42&t_id=32",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ocxt.com/archives/28",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/24229",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1992",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34590",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/4009",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://moaxb.blogspot.com/2007/05/moaxb-29-edraw-office-viewer-component.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/36045",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25418",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://shinnai.altervista.org/viewtopic.php?id=42&t_id=32",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ocxt.com/archives/28",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/24229",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1992",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34590",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/4009",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long first argument to the HttpDownloadFile method."
    },
    {
      "lang": "es",
      "value": "Un desbordamiento de búfer en un cierto control ActiveX en el EDraw Office Viewer Component (edrawofficeviewer.ocx) versión 4.0.5.20 y otras versiones anteriores a 5.0, permite a atacantes remotos causar una denegación de servicio (bloqueo de Internet Explorer versión 7) o ejecutar código arbitrario por medio de un primer argumento largo en el Método HttpDownloadFile."
    }
  ],
  "lastModified": "2026-06-16T22:41:12.163",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:edraw:office_viewer_component:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B4A5C32-2C26-42D7-8039-EAE1A7383D48",
              "versionEndIncluding": "5.0"
            },
            {
              "criteria": "cpe:2.3:a:edraw:office_viewer_component:4.0.5.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFF5C7C7-D888-4D9E-B4DA-68B6978C02DB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}