← All CVEs

CVE-2007-4475

high · 9.3

Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers to execute arbitrary code via a long argument to the SaveViewToSessionFile method.

9.3
CVSS
40.3%
EPSS (exploit prob.)
99th
EPSS percentile
2009-04-01
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
sapsapguiall versions
sapsapgui<= 7.10
sapsapgui4.6
sapsapgui4.6
sapsapgui4.6a
sapsapgui4.6a
sapsapgui4.6b
sapsapgui4.6b
sapsapgui4.6c
sapsapgui4.6c
sapsapgui4.6d
sapsapgui4.6d
sapsapgui6.40

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-4475