CVE-2007-1770
Estado: ModificadaAlta (10)—
Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 17%
- Percentil entre todas las CVEs puntuadas: 97
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-120
Referencias
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=507
- http://secunia.com/advisories/24639
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1260
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1261
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1262
- http://www.securityfocus.com/bid/23175
- http://www.securitytracker.com/id?1017874
- http://www.vupen.com/english/advisories/2007/1140
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33282
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33457
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=507
- http://secunia.com/advisories/24639
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1260
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1261
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1262
- http://www.securityfocus.com/bid/23175
- http://www.securitytracker.com/id?1017874
- http://www.vupen.com/english/advisories/2007/1140
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33282
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33457
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-1770",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-03-30T01:19:00.000",
"references": [
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=507",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/24639",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1260",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1261",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1262",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/23175",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1017874",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1140",
"tags": [
"Broken Link",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33282",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33457",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=507",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/24639",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1260",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1261",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1262",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/23175",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1017874",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1140",
"tags": [
"Broken Link",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33282",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33457",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests."
},
{
"lang": "es",
"value": "Un desbordamiento de búfer en el servicio ArcSDE (giomgr) en Environmental Systems Research Institute (ESRI) ArcGIS versiones anteriores a 9.2 Service Pack 2, cuando se usan tres configuraciones de ArcSDE por niveles, permite a atacantes remotos causar una denegación de servicio (bloqueo de giomgr) y ejecutar código arbitrario por medio de parámetros largos en peticiones especialmente diseñadas."
}
],
"lastModified": "2026-06-16T22:38:15.520",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:esri:arcsde:8.3:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A82958BE-AD51-4B8A-880F-78A24EC0D5B3"
},
{
"criteria": "cpe:2.3:a:esri:arcsde:8.3:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDD89080-78A0-45D6-AF09-249F060C90EE"
},
{
"criteria": "cpe:2.3:a:esri:arcsde:9.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "66DEC285-378A-45FA-9F4A-C8D09BC1BCD6"
},
{
"criteria": "cpe:2.3:a:esri:arcsde:9.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "660B27C9-40DA-4EF3-AE23-EE504311E18F"
},
{
"criteria": "cpe:2.3:a:esri:arcsde:9.0:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF458849-D6F1-4D96-B444-AA87C8F07FBE"
},
{
"criteria": "cpe:2.3:a:esri:arcsde:9.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B8555DEF-F5C8-4D43-B5FC-E40D31914216"
},
{
"criteria": "cpe:2.3:a:esri:arcsde:9.1:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BCB60950-B362-48CD-A174-C03A4ADD9670"
},
{
"criteria": "cpe:2.3:a:esri:arcsde:9.1:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0DB4846B-DB82-484C-815C-04D8748F8759"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}