// For flags

CVE-2007-2855

 

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2856.

Un desbordamiento de búfer en un cierto control ActiveX en biblioteca DartZipLite.dll versión 1.8.5.3 en Dart ZipLite Compression para ActiveX, permite a atacantes remotos asistidos por el usuario ejecutar código arbitrario por medio de un primer argumento largo en la función QuickZip, un problema relacionado con CVE-2007-2856.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-05-24 CVE Reserved
  • 2007-05-24 CVE Published
  • 2024-06-11 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dart
Search vendor "Dart"
Dart Ziplite Compression
Search vendor "Dart" for product "Dart Ziplite Compression"
1.8.5.3
Search vendor "Dart" for product "Dart Ziplite Compression" and version "1.8.5.3"
-
Affected