9.3
CVSSv2

CVE-2007-6387

Published: 15/12/2007 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping, ProSeries, QuickBooks, Quicken, QuickTax, and TurboTax, allow remote malicious users to execute arbitrary code via long arguments to the (1) GetHistory, (2) GetSeedQuery, (3) SetSeedQuery, and possibly other methods. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

intuit quicken

intuit quicktax

intuit bookkeeping

vantage linquistics answerworks

intuit turbo tax

microsoft activex 4.0.0.42

intuit proseries

intuit quickbooks

Exploits

<!-- Vantage Linguistics AnswerWorks 4 API ActiveX Control Buffer Overflow Exploit Vulnerability discovered by Parvez Anwar Exploit written by eb References: secuniacom/advisories/26566/ CVE-2007-6387 Tested on Windows XP SP2(fully patched) English, IE6, awApi4dll version 40044 Note that Microsoft "killbitted" this class id as ...
Vantage Linguistics AnswerWorks version 4 API ActiveX control buffer overflow exploit ...