Vulnerability Name: | CVE-2007-3675 (CCN-37057) | ||||||||
Assigned: | 2007-10-09 | ||||||||
Published: | 2007-10-09 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Multiple format string vulnerabilities in the kavwebscan.CKAVWebScan ActiveX control (kavwebscan.dll) in Kaspersky Online Scanner before 5.0.98 allow remote attackers to execute arbitrary code via format string specifiers in "various string formatting functions," which trigger heap-based buffer overflows. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-134 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-3675 Source: IDEFENSE Type: UNKNOWN 20071010 Kaspersky Web Scanner ActiveX Format String Vulnerability Source: CCN Type: SA27187 Kaspersky Online Scanner ActiveX Control Format String Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 27187 Source: CCN Type: SECTRACK ID: 1018800 Kaspersky Online Scanner Format String Flaw in ActiveX Control Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: Patch 1018800 Source: CCN Type: Kaspersky Web site Kaspersky Lab announces the release of a new version of its free Kaspersky Online Scanner Source: CONFIRM Type: Patch http://www.kaspersky.com/news?id=207575572 Source: CCN Type: OSVDB ID: 37713 Kaspersky Online Scanner kavwebscan.CKAVWebScan ActiveX (kavwebscan.dll) Format String Arbitrary Code Execution Source: BID Type: Patch 26004 Source: CCN Type: BID-26004 Kaspersky Online Scanner KAVWebScan.DLL ActiveX Control Format String Vulnerability Source: VUPEN Type: UNKNOWN ADV-2007-3455 Source: XF Type: UNKNOWN kaspersky-online-activex-format-string(37057) Source: XF Type: UNKNOWN kaspersky-online-activex-format-string(37057) Source: CCN Type: iDefense PUBLIC ADVISORY: 10.10.07 Kaspersky Web Scanner ActiveX Format String Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |