{ "id": "CVE-2007-1819", "sourceIdentifier": "cve@mitre.org", "published": "2007-04-02T23:19:00.000", "lastModified": "2017-07-29T01:31:01.987", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for Mercury Quality Center 9.0 before Patch 12.1, and 8.2 SP1 before Patch 32, allows remote attackers to execute arbitrary code via a long ProgColor property." }, { "lang": "es", "value": "Un desbordamiento de b\u00fafer en la regi\u00f3n stack de la memoria en el control ActiveX SPIDERLib.Loader (Spider90.ocx) versi\u00f3n 9.1.0.4353 en TestDirector (TD) para Mercury Quality Center versi\u00f3n 9.0 anterior al Parche 12.1 y versi\u00f3n 8.2 SP1 anterior al Parche 32, permite a atacantes remotos ejecutar c\u00f3digo arbitrario por medio de una propiedad ProgColor larga." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE", "baseScore": 9.3 }, "baseSeverity": "HIGH", "exploitabilityScore": 8.6, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": true, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-119" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:hp:mercury_quality_center:8.2:sp1:*:*:*:*:*:*", "matchCriteriaId": "BA438217-B2C1-4391-9CFE-A902F01F1C0E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:hp:mercury_quality_center:9.0:*:*:*:*:*:*:*", "matchCriteriaId": "C357686A-D5A5-439A-A14A-FF5B53F0CCEF" } ] } ] } ], "references": [ { "url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00901872", "source": "cve@mitre.org" }, { "url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=497", "source": "cve@mitre.org" }, { "url": "http://securitytracker.com/id?1017835", "source": "cve@mitre.org" }, { "url": "http://webnotes.merc-int.com/patches.nsf/c4d68388a23535dc422567d0004bbae2/7a0f7f0efc7905fdc225729f004cf387?OpenDocument", "source": "cve@mitre.org" }, { "url": "http://webnotes.merc-int.com/patches.nsf/c4d68388a23535dc422567d0004bbae2/cf109e434c7765eac22572a4006c6e94?OpenDocument", "source": "cve@mitre.org" }, { "url": "http://www.kb.cert.org/vuls/id/589097", "source": "cve@mitre.org", "tags": [ "US Government Resource" ] }, { "url": "http://www.securityfocus.com/bid/23239", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2007/1185", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33353", "source": "cve@mitre.org" } ] }