CVE-2007-5909

high

Description

Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910.

References

http://www.zerodayinitiative.com/advisories/ZDI-07-059.html

http://www.vupen.com/english/advisories/2007/3697

http://www.vupen.com/english/advisories/2007/3596

http://www.securityfocus.com/bid/26175

http://www.securityfocus.com/archive/1/483102/100/0/threaded

http://www.securityfocus.com/archive/1/482664

http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21272836

http://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21271111

http://vuln.sg/lotusnotes702sam-en.html

http://vuln.sg/lotusnotes702mif-en.html

http://vuln.sg/lotusnotes702doc-en.html

http://vuln.sg/lotusnotes702-en.html

http://securitytracker.com/id?1018886

http://securitytracker.com/id?1018853

http://securityresponse.symantec.com/avcenter/security/Content/2007.11.01c.html

http://securityreason.com/securityalert/3357

http://secunia.com/advisories/27304

Details

Source: Mitre, NVD

Published: 2007-11-10

Updated: 2018-10-15

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High