Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-1682 | First vendor Publication | 2008-08-27 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists, or (4) DeleteFile method. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1682 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
47794 | SoftArtisans XFile FileManager ActiveX (SAFmgPws.dll) Multiple Method Overflows Multiple buffer overflows exist in XFile. The FileManager ActiveX control fails to validate data passed to the BuildPath, GetDriveName, DriveExists, and DeleteFile methods resulting in a stack overflow. With a specially crafted website, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | SoftArtisans XFile FileManager ActiveX Control access attempt RuleID : 16714 - Revision : 7 - Type : BROWSER-PLUGINS |
2014-01-10 | SoftArtisans XFile FileManager ActiveX function call unicode access RuleID : 14234 - Revision : 5 - Type : WEB-ACTIVEX |
2014-01-10 | SoftArtisans XFile FileManager ActiveX function call access RuleID : 14233 - Revision : 9 - Type : BROWSER-PLUGINS |
2014-01-10 | SoftArtisans XFile FileManager ActiveX clsid unicode access RuleID : 14232 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | SoftArtisans XFile FileManager ActiveX clsid access RuleID : 14231 - Revision : 10 - Type : BROWSER-PLUGINS |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:13:38 |
|
2024-11-28 12:11:53 |
|
2021-05-04 12:05:33 |
|
2021-04-22 01:06:08 |
|
2020-05-23 13:16:48 |
|
2020-05-23 01:38:00 |
|
2020-05-23 00:19:30 |
|
2016-04-26 15:55:21 |
|
2014-01-19 21:23:59 |
|
2013-05-11 10:21:44 |
|