Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-4916

Опубликовано: 17 сент. 2007
Источник: nvd
CVSS2: 10
EPSS Высокий

Описание

Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hp:photo_and_imaging_gallery:1.1:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:h:hp:all-in-on_printer:*:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.71291
Высокий

10 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

github
почти 4 года назад

Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.

EPSS

Процентиль: 99%
0.71291
Высокий

10 Critical

CVSS2

Дефекты

CWE-119