CVE-2007-1281
Status: ModifiedHigh (7.8)—
Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.01%
- Percentile among all scored CVEs: 87
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=485
- http://secunia.com/advisories/24391
- http://www.securityfocus.com/bid/22795
- http://www.securitytracker.com/id?1017718
- http://www.vupen.com/english/advisories/2007/0810
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32797
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=485
- http://secunia.com/advisories/24391
- http://www.securityfocus.com/bid/22795
- http://www.securitytracker.com/id?1017718
- http://www.vupen.com/english/advisories/2007/0810
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32797
Raw JSON (NVD)
Show
{
"id": "CVE-2007-1281",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-03-06T01:19:00.000",
"references": [
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=485",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/24391",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/22795",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1017718",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/0810",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/32797",
"source": "cve@mitre.org"
},
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=485",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/24391",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/22795",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1017718",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/0810",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/32797",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression."
},
{
"lang": "es",
"value": "Kaspersky AntiVirus Engine 6.0.1.411 para Windows y 5.5-10 para Linux permite a atacantes remotos provocar una denegación de servicio (agotamiento de CPU) mediante un archivo comprimido con UPX manipulado con un desplazamiento (offset) negativo, lo cual dispara un bucle infinito durante la extracción."
}
],
"lastModified": "2026-06-16T22:37:17.250",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:all_windows:abstract_cpe:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "595E948E-30B9-4E08-B7A7-73AFD1C29FA2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:kaspersky_lab:kaspersky_antivirus_engine:6.0.1.411:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDEAD0D1-CA5E-4B27-9A36-5614F4FDF4F1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:ia32_64-bit:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4F8CD59E-22A6-4B56-8834-B8A18FBC1A7D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:kaspersky_lab:kaspersky_antivirus_engine:5.5.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F1FFFF2C-7C8F-42EE-8B37-AAB833112B16"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}