CVE-2007-3435
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 35%
from disclosure to weapon1047 days
Published on NVDJun 27
1st PoC+1047d
metasploitJun 22
exploitation probability
35%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote attackers to execute arbitrary code via a long argument.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/4094unverifiedexploitdbwww.exploit-db.com/exploits/16565unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://goodfellas.shellcode.com.ar/own/VULWAR200706223.txthttp://osvdb.org/37482http://secunia.com/advisories/25788https://exchange.xforce.ibmcloud.com/vulnerabilities/35011https://www.exploit-db.com/exploits/4094http://www.securityfocus.com/archive/1/472189/100/0/threadedhttp://www.securityfocus.com/bid/24596http://www.vupen.com/english/advisories/2007/2305