10
CVSSv2

CVE-2007-4916

Published: 17/09/2007 Updated: 15/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.

Vulnerable Product Search on Vulmon Subscribe to Product

hp photo and imaging gallery 1.1

hp all-in-on printer

Exploits

: GOODFELLAS Security Research TEAM : : goodfellasshellcodecomar : ActiveX hpqutil!ListFiles hpqutildll - Remote heap overflow ============================================================= Internal ID: VULWAR200706041 introduction ------------ GOODFELLAS security research team has found a bug in a dll included in at least the f ...
source: wwwsecurityfocuscom/bid/25697/info The CFileFind::FindFile method in the MFC library for Microsoft Windows is prone to a buffer-overflow vulnerability because the method fails to perform adequate boundary checks of user-supplied input Successfully exploiting this issue may allow attackers to execute arbitrary code in the context ...