CVE-2007-4991
medium · 5The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination IP address of another user's session) via an empty packet.
5
CVSS
16.1%
EPSS (exploit prob.)
97th
EPSS percentile
2007-09-21
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | isa_server | 2004 |
| microsoft | isa_server | 2004 |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/45906
- http://www.securityfocus.com/bid/25753
- http://www.securitytracker.com/id?1018727
- http://www.zerodayinitiative.com/advisories/ZDI-07-053.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36715
- http://osvdb.org/45906
- http://www.securityfocus.com/bid/25753
- http://www.securitytracker.com/id?1018727
- http://www.zerodayinitiative.com/advisories/ZDI-07-053.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36715
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-4991