CVE-2007-1819
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 40%
from disclosure to weapon2 days
Published on NVDApr 2
1st PoC+2d
metasploit+2d
exploitation probability
40%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for Mercury Quality Center 9.0 before Patch 12.1, and 8.2 SP1 before Patch 32, allows remote attackers to execute arbitrary code via a long ProgColor property.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/16580unverifiedexploitdbwww.exploit-db.com/exploits/3661unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00901872http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=497http://secunia.com/advisories/24692http://securitytracker.com/id?1017835https://exchange.xforce.ibmcloud.com/vulnerabilities/33353http://webnotes.merc-int.com/patches.nsf/c4d68388a23535dc422567d0004bbae2/7a0f7f0efc7905fdc225729f004cf387?OpenDocumenthttp://webnotes.merc-int.com/patches.nsf/c4d68388a23535dc422567d0004bbae2/cf109e434c7765eac22572a4006c6e94?OpenDocumenthttp://www.kb.cert.org/vuls/id/589097http://www.securityfocus.com/bid/23239http://www.vupen.com/english/advisories/2007/1185