Lucene search

K
cve[email protected]CVE-2007-3895
HistoryDec 12, 2007 - 12:46 a.m.

CVE-2007-3895

2007-12-1200:46:00
CWE-119
web.nvd.nist.gov
24
microsoft
directshow
buffer overflow
remote code execution
wav
avi
microsoft directx
cve-2007-3895
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.908 High

EPSS

Percentile

98.9%

Buffer overflow in Microsoft DirectShow in Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted (1) WAV or (2) AVI file.

Affected configurations

NVD
Node
microsoftwindows_2000sp4
AND
microsoftdirectxMatch7.0
OR
microsoftdirectxMatch8.1
Node
microsoftwindows_2000sp4
OR
microsoftwindows_2003_serverx64
OR
microsoftwindows_2003_serversp1
OR
microsoftwindows_2003_serversp1itanium
OR
microsoftwindows_2003_serversp2
OR
microsoftwindows_2003_serversp2itanium
OR
microsoftwindows_2003_serversp2x64
OR
microsoftwindows_xpx64
OR
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp2x64
AND
microsoftdirectxMatch9.0c
Node
microsoftwindows_vistagold
OR
microsoftwindows_vistagoldx64
AND
microsoftdirectxMatch10.0

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.908 High

EPSS

Percentile

98.9%