« Volver al listado

CVE-2007-6009

Estado: ModificadaAlta (9.3)—

Multiple buffer overflows in ACD products allow user-assisted remote attackers to execute arbitrary code via a long section string in a (1) XBM or (2) XPM file to (a) ID_X.apl or (b) IDE_ACDStd.apl. NOTE: the PSP and LHA vectors are already covered by CVE-2007-4344 and CVE-2007-6007. NOTE: these might be integer overflows rather than buffer overflows.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-6009",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-11-15T22:46:00.000",
  "references": [
    {
      "url": "http://osvdb.org/45278",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.acdsee.com/support/knowledgebase/article?id=2800",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/26554",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/45278",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.acdsee.com/support/knowledgebase/article?id=2800",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/26554",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple buffer overflows in ACD products allow user-assisted remote attackers to execute arbitrary code via a long section string in a (1) XBM or (2) XPM file to (a) ID_X.apl or (b) IDE_ACDStd.apl.  NOTE: the PSP and LHA vectors are already covered by CVE-2007-4344 and CVE-2007-6007.  NOTE: these might be integer overflows rather than buffer overflows."
    },
    {
      "lang": "es",
      "value": "Múltiples desbordamientos de búfer en productos de ACD permite a atacantes remotos con la complicidad del usuario ejecutar código de su elección mediante una cadena de sección larga en un fichero (1) XBM o (2) XPM a (a) ID_X.apl o (b) IDE_ACDStd.apl. NOTA: los vectores PSP y LHA están ya cubiertos por CVE-2007-4344 y CVE-2007-6007. NOTA: se podría tratar de desbordamiento de enteros más que de desbordamientos de búfer."
    }
  ],
  "lastModified": "2026-06-16T22:47:14.997",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:acdsee:photo_editor:4.0:build_195:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8948DF3-7A78-4607-B3B0-C936B3C553F8"
            },
            {
              "criteria": "cpe:2.3:a:acdsee:photo_manager:9.0:build_108:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C99826F-7ECF-495D-B8C0-9EAFDC425E8A"
            },
            {
              "criteria": "cpe:2.3:a:acdsee:pro_photo_manager:8.1:build_99:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "306A23E6-74FF-40E5-A5D4-C6372A2907C7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}