{ "id": "CVE-2007-2494", "sourceIdentifier": "cve@mitre.org", "published": "2007-05-04T00:19:00.000", "lastModified": "2024-11-21T00:30:55.670", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) Save, (6) SaveWebFile, (7) HttpDownloadFile, (8) Open, or (9) OpenWebFile property value. NOTE: some of these details are obtained from third party information." }, { "lang": "es", "value": "M\u00faltiples desbordamientos de b\u00fafer basado en pila en el control ActiveX PowerPointOCX en PowerPointViewer.ocx 3.1.0.3 permiten a atacantes remotos provocar una denegaci\u00f3n de servicio (c\u00e1ida de Internet Explorer 7) mediante un valor de propiedad largo (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) Save, (6) SaveWebFile, (7) HttpDownloadFile, (8) Open, \u00f3 (9) OpenWebFile.\r\nNOTA: algunos de estos detalles se han obtenido de informaci\u00f3n de terceros." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C", "baseScore": 10.0, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE" }, "baseSeverity": "HIGH", "exploitabilityScore": 10.0, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:office_ocx:powerpoint_viewer_ocx:*:*:*:*:*:*:*:*", "versionEndIncluding": "3.1.0.3", "matchCriteriaId": "F40C1A51-76FF-4A0A-B0DD-D17D6B68865A" } ] } ] } ], "references": [ { "url": "http://moaxb.blogspot.com/2007/05/moaxb-01-powerpointviewerocx-31.html", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/34332", "source": "cve@mitre.org" }, { "url": "http://secunia.com/advisories/25092", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/23733", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2007/1612", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34013", "source": "cve@mitre.org" }, { "url": "https://www.exploit-db.com/exploits/3826", "source": "cve@mitre.org" }, { "url": "http://moaxb.blogspot.com/2007/05/moaxb-01-powerpointviewerocx-31.html", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/34332", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://secunia.com/advisories/25092", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://www.securityfocus.com/bid/23733", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.vupen.com/english/advisories/2007/1612", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34013", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://www.exploit-db.com/exploits/3826", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }