CVE-2007-2238
high · 9.3Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1) CheckForUpdates or (2) UpdateComponents methods.
9.3
CVSS
45.5%
EPSS (exploit prob.)
99th
EPSS percentile
2009-04-16
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | intelligent_application_gateway_2007 | all versions |
| microsoft | intelligent_application_gateway_2007 | <= 3.7 |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/34725
- http://www.kb.cert.org/vuls/id/789121
- http://www.securityfocus.com/bid/34532
- http://www.vupen.com/english/advisories/2009/1061
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49888
- http://secunia.com/advisories/34725
- http://www.kb.cert.org/vuls/id/789121
- http://www.securityfocus.com/bid/34532
- http://www.vupen.com/english/advisories/2009/1061
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49888
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-2238