CVE-2007-4475
high · 9.3Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers to execute arbitrary code via a long argument to the SaveViewToSessionFile method.
9.3
CVSS
40.3%
EPSS (exploit prob.)
99th
EPSS percentile
2009-04-01
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sap | sapgui | all versions |
| sap | sapgui | <= 7.10 |
| sap | sapgui | 4.6 |
| sap | sapgui | 4.6 |
| sap | sapgui | 4.6a |
| sap | sapgui | 4.6a |
| sap | sapgui | 4.6b |
| sap | sapgui | 4.6b |
| sap | sapgui | 4.6c |
| sap | sapgui | 4.6c |
| sap | sapgui | 4.6d |
| sap | sapgui | 4.6d |
| sap | sapgui | 6.40 |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/34559
- http://www.kb.cert.org/vuls/id/985449
- http://www.securityfocus.com/bid/34310
- http://www.vupen.com/english/advisories/2009/0892
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49543
- https://service.sap.com/sap/support/notes/1153794
- http://secunia.com/advisories/34559
- http://www.kb.cert.org/vuls/id/985449
- http://www.securityfocus.com/bid/34310
- http://www.vupen.com/english/advisories/2009/0892
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49543
- https://service.sap.com/sap/support/notes/1153794
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-4475