Lucene search

K
cve[email protected]CVE-2007-6026
HistoryNov 20, 2007 - 12:46 a.m.

CVE-2007-6026

2007-11-2000:46:00
CWE-119
web.nvd.nist.gov
38
cve-2007-6026
microsoft
msjet40.dll
stack-based buffer overflow
access 2003
office 2003
user-assisted
arbitrary code
mdb file
database file

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.842 High

EPSS

Percentile

98.5%

Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.

Affected configurations

NVD
Node
microsoftjetMatch4.0.8618.0
OR
microsoftofficeMatch2003sp3
Node
microsoftwindows_2000
OR
microsoftwindows_2003_server
OR
microsoftwindows_ntMatch4.0
OR
microsoftwindows_xpsp2

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.842 High

EPSS

Percentile

98.5%