CVE-2007-5257
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 15%
exploitation probability
15%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169.
Affected products
n/a · n/apublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/4474unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/37724http://secunia.com/advisories/27017https://exchange.xforce.ibmcloud.com/vulnerabilities/36879http://shinnai.altervista.org/exploits/txt/TXT_O5FvsIzILBHQr7QbK2kD.htmlhttps://www.exploit-db.com/exploits/4474http://www.securityfocus.com/bid/25892http://www.vupen.com/english/advisories/2007/3329