2024-12-08 03:06:42 +00:00

124 lines
3.9 KiB
JSON

{
"id": "CVE-2007-2496",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-05-04T00:19:00.000",
"lastModified": "2024-11-21T00:30:55.940",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value."
},
{
"lang": "es",
"value": "El control ActiveX WordOCX en WordViewer.ocx 3.2.0.5 permite a atacantes remotos provocar una denegaci\u00f3n de servicio (c\u00e1ida de Internet Explorer 7) mediante un valor de propiedad largo (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, \u00f3 (12) ShowWordStandardDialog."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"baseScore": 7.8,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:office_ocx:word_viewer_ocx:3.2.0.5:*:*:*:*:*:*:*",
"matchCriteriaId": "B7C9AA67-6092-4FB5-BFFD-8A35B16DC2A7"
}
]
}
]
}
],
"references": [
{
"url": "http://moaxb.blogspot.com/2007/05/moaxb-03-wordviewerocx-32-multiple_03.html",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/34334",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25100",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/23784",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1634",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34027",
"source": "cve@mitre.org"
},
{
"url": "http://moaxb.blogspot.com/2007/05/moaxb-03-wordviewerocx-32-multiple_03.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/34334",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/25100",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/23784",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/1634",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34027",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}