« Volver al listado

CVE-2007-3168

Estado: ModificadaAlta (7.8)—

A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files via the DeleteLocalFile method.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-3168",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:C",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 7.8,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-06-11T22:30:00.000",
  "references": [
    {
      "url": "http://moaxb.blogspot.com/2007/05/moaxb-28-edraw-office-viewer-component.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/36044",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/25418",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://shinnai.altervista.org/viewtopic.php?id=42&t_id=31",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ocxt.com/archives/28",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/24230",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1992",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34588",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/4010",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://moaxb.blogspot.com/2007/05/moaxb-28-edraw-office-viewer-component.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/36044",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25418",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://shinnai.altervista.org/viewtopic.php?id=42&t_id=31",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ocxt.com/archives/28",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/24230",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1992",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34588",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/4010",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files via the DeleteLocalFile method."
    },
    {
      "lang": "es",
      "value": "Un cierto control ActiveX en el EDraw Office Viewer Component (edrawofficeviewer.ocx) versión 4.0.5.20 y otras versiones anteriores a 5.0, permite a atacantes remotos eliminar archivos arbitrarios por medio del método DeleteLocalFile."
    }
  ],
  "lastModified": "2026-06-16T22:41:12.043",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:edraw:office_viewer_component:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B4A5C32-2C26-42D7-8039-EAE1A7383D48",
              "versionEndIncluding": "5.0"
            },
            {
              "criteria": "cpe:2.3:a:edraw:office_viewer_component:4.0.5.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFF5C7C7-D888-4D9E-B4DA-68B6978C02DB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}