Lucene search

K
cveMitreCVE-2007-6654
HistoryJan 04, 2008 - 11:46 a.m.

CVE-2007-6654

2008-01-0411:46:00
CWE-119
mitre
web.nvd.nist.gov
32
cve-2007-6654
buffer overflow
remote code execution
activex control
macrovision installshield update service web agent

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.963

Percentile

99.6%

Buffer overflow in a certain ActiveX control in Macrovision InstallShield Update Service Web Agent 5.1.100.47363 allows remote attackers to execute arbitrary code via a long string in the ProductCode argument (second argument) to the DownloadAndExecute method, a different vulnerability than CVE-2007-0321, CVE-2007-2419, and CVE-2007-5660.

Affected configurations

Nvd
Node
macrovisionupdate_serviceMatch5.1.100_47363
VendorProductVersionCPE
macrovisionupdate_service5.1.100_47363cpe:2.3:a:macrovision:update_service:5.1.100_47363:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.963

Percentile

99.6%