← All CVEs

CVE-2007-6506

high · 9.3

The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.

9.3
CVSS
16.3%
EPSS (exploit prob.)
97th
EPSS percentile
2007-12-20
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
hpsoftware_update<= 4.000.005.007
hpsoftware_update3.0.8.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-6506