10
CVSSv2

CVE-2007-5257

Published: 06/10/2007 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and previous versions allows remote malicious users to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169.

Vulnerable Product Search on Vulmon Subscribe to Product

edraw office viewer component

Exploits

<pre> <code><span style="font: 10pt Courier New;"><span class="general1-symbol"><body bgcolor="#E0E0E0">----------------------------------------------------------------------------- <b>EDraw Office Viewer Component 53 "FtpDownloadFile()" Remote BoF</b> url: wwwocxtcom/officeviewerphp Author: ...