CVE-2007-6699
AOL Picture Editor 'YGPPicEdit.dll' ActiveX Control 9.5.1.8 - Multiple Buffer Overflow Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote attackers to cause a denial of service (browser crash) via a long string in the (1) DisplayName, (2) FinalSavePath, (3) ForceSaveTo, (4) HiddenControls, (5) InitialEditorScreen, (6) Locale, (7) Proxy, and (8) UserAgent property values.
Múltiples desbordamientos de búfer en el control ActiveX AIM PicEditor 9.5.1.8 de YGPPicEdit.dll en AOL You've Got Pictures (YGP) Picture Editor. Permiten a atacantes remotos causar una denegación de servicio (caída del navegador) a través de una cadena larga en los valores de propiedades (1) DisplayName, (2) FinalSavePath, (3) ForceSaveTo, (4) HiddenControls, (5) InitialEditorScreen, (6) Locale, (7) Proxy y (8) UserAgent.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-12-25 First Exploit
- 2008-02-04 CVE Reserved
- 2008-02-04 CVE Published
- 2024-08-07 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://osvdb.org/41198 | Vdb Entry | |
http://seclists.org/fulldisclosure/2007/Dec/0574.html | Mailing List |
|
http://www.securitytracker.com/id?1019143 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/30936 | 2007-12-25 | |
http://seclists.org/fulldisclosure/2007/Dec/0561.html | 2024-08-07 | |
http://www.securityfocus.com/bid/27026 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Aol Search vendor "Aol" | Ygp Piceditor Activex Control Search vendor "Aol" for product "Ygp Piceditor Activex Control" | 9.5.1.8 Search vendor "Aol" for product "Ygp Piceditor Activex Control" and version "9.5.1.8" | - |
Affected
|