Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-4467

Опубликовано: 31 авг. 2007
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Multiple stack-based buffer overflows in the Oracle JInitiator ActiveX control (beans.ocx) 1.1.8.16 and earlier, as used by Oracle Forms applications from Oracle and third parties, allow remote attackers to execute arbitrary code via unspecified "initialization parameters." NOTE: it was later reported that 1.1.8.3 through 1.1.8.25, and probably 1.1.5.x and 1.1.7.x, are affected.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:oracle:jinitiator:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jinitiator:1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jinitiator:1.1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jinitiator:1.1.8.16:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jinitiator:1.1.8.25:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.33324
Средний

9.3 Critical

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
почти 4 года назад

Multiple stack-based buffer overflows in the Oracle JInitiator ActiveX control (beans.ocx) 1.1.8.16 and earlier, as used by Oracle Forms applications from Oracle and third parties, allow remote attackers to execute arbitrary code via unspecified "initialization parameters." NOTE: it was later reported that 1.1.8.3 through 1.1.8.25, and probably 1.1.5.x and 1.1.7.x, are affected.

EPSS

Процентиль: 97%
0.33324
Средний

9.3 Critical

CVSS2

Дефекты

CWE-20