Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-2240 | First vendor Publication | 2007-08-15 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 5.8 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2240 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Hardware | 1 | |
Hardware | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2010-07-08 | Name : Cumulative Security Update for Internet Explorer (937143) File : nvt/ms07-045.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
39555 | IBM Lenovo Access Support acpRunner ActiveX acpcontroller.dll / acpir.dll Dig... |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Internet Explorer CSS strings parsing memory corruption attempt RuleID : 17645 - Revision : 9 - Type : BROWSER-IE |
2014-01-10 | Microsoft Package and Deployment Wizard ActiveX function call unicode access RuleID : 13324 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Package and Deployment Wizard ActiveX function call access RuleID : 13323 - Revision : 11 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Package and Deployment Wizard ActiveX clsid unicode access RuleID : 13322 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Package and Deployment Wizard ActiveX clsid access RuleID : 13321 - Revision : 17 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Internet Explorer CSS memory corruption exploit RuleID : 12277 - Revision : 19 - Type : BROWSER-IE |
2014-01-10 | Microsoft Visual Basic 6 TypeLibInfo ActiveX function call unicode access RuleID : 12276 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Visual Basic 6 TypeLibInfo ActiveX function call access RuleID : 12275 - Revision : 9 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Visual Basic 6 TypeLibInfo ActiveX clsid unicode access RuleID : 12274 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Visual Basic 6 TypeLibInfo ActiveX clsid access RuleID : 12273 - Revision : 10 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Visual Basic 6 TLIApplication ActiveX function call unicode access RuleID : 12272 - Revision : 8 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Visual Basic 6 TLIApplication ActiveX function call access RuleID : 12271 - Revision : 8 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Visual Basic 6 TLIApplication ActiveX function call RuleID : 12270 - Revision : 16 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Visual Basic 6 TLIApplication ActiveX clsid access RuleID : 12269 - Revision : 19 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Visual Basic 6 SearchHelper ActiveX function call unicode access RuleID : 12268 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Visual Basic 6 SearchHelper ActiveX function call access RuleID : 12267 - Revision : 10 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Visual Basic 6 SearchHelper ActiveX clsid unicode access RuleID : 12266 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Visual Basic 6 SearchHelper ActiveX clsid access RuleID : 12265 - Revision : 11 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Visual Basic 6 PDWizard.File ActiveX function call unicode access RuleID : 12264 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Visual Basic 6 PDWizard.File ActiveX function call access RuleID : 12263 - Revision : 9 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Visual Basic 6 PDWizard.File ActiveX clsid unicode access RuleID : 12262 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Visual Basic 6 PDWizard.File ActiveX clsid access RuleID : 12261 - Revision : 10 - Type : BROWSER-PLUGINS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-08-14 | Name : Arbitrary code can be executed on the remote host through the web client. File : smb_nt_ms07-045.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:16:33 |
|
2024-11-28 12:12:07 |
|
2021-05-04 12:05:41 |
|
2021-04-22 01:06:15 |
|
2020-05-23 00:19:38 |
|
2018-10-13 00:22:37 |
|
2017-07-29 12:02:11 |
|
2016-06-28 16:24:20 |
|
2016-04-26 16:02:31 |
|
2014-02-17 10:39:56 |
|
2013-05-11 10:23:55 |
|