CVE-2007-2980

high

Description

Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long DriverName property, a different ActiveX control than CVE-2007-2827.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/34528

http://www.vupen.com/english/advisories/2007/1972

http://www.shinnai.altervista.org/moaxb/20070527/leadrasterisistxt.html

http://secunia.com/advisories/25433

http://osvdb.org/36043

http://moaxb.blogspot.com/2007/05/moaxb-27-leadtools-raster-isis-object.html

Details

Source: Mitre, NVD

Published: 2007-06-01

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.08775