CVE-2007-3794
Last modified
CVE-2007-3794 is a vulnerability of currently unknown severity. Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this software, allows attackers to have an unknown impact via certain GIF images, related to use of GIF image processing APIs by a Java application.. EPSS estimates a 2.19% chance of exploitation in the next 30 days.
Description
Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this software, allows attackers to have an unknown impact via certain GIF images, related to use of GIF image processing APIs by a Java application.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Cosminexus Application Server | 05_00_05_00_h |
| Hitachi | Cosminexus Application Server | 05_01_05_01_k |
| Hitachi | Cosminexus Application Server | 05_05_05_00_o |
| Hitachi | Cosminexus Application Server | 06_00_06_00_g |
| Hitachi | Cosminexus Application Server | 06_02_06_02_f |
| Hitachi | Cosminexus Application Server | 06_50_06_50_e |
| Hitachi | Cosminexus Application Server | 06_51_06_51_g |
| Hitachi | Cosminexus Client | 06_00_06_00_g |
| Hitachi | Cosminexus Client | 06_02_06_02_f |
| Hitachi | Cosminexus Client | 06_50_06_50_e |
| Hitachi | Cosminexus Client | 06_51_06_51_g |
| Hitachi | Cosminexus Developer | 05_00_05_00_h |
| Hitachi | Cosminexus Developer | 05_01_05_01_k |
| Hitachi | Cosminexus Developer | 05_05_05_05_o |
| Hitachi | Cosminexus Developer | 06_00_06_00_g |
| Hitachi | Cosminexus Developer | 06_02_06_02_f |
| Hitachi | Cosminexus Developer | 06_50_06_50_e |
| Hitachi | Cosminexus Developer | 06_51_06_51_g |
| Hitachi | Cosminexus Server | 04_00_04_00_a |
| Hitachi | Cosminexus Server | 04_01_04_01_a |
| Hitachi | Cosminexus Studio | 04_00_04_00_a |
| Hitachi | Cosminexus Studio | 04_01_04_01_a |
| Hitachi | Cosminexus Studio | 05_05_05_05_o |
| Hitachi | Ucosminexus Application Server | 06_70_06_70_a |
| Hitachi | Ucosminexus Application Server | 06_70_06_70_b |
| Hitachi | Ucosminexus Application Server | 06_71_06_71_b |
| Hitachi | Ucosminexus Application Server | 07_00_07_20 |
| Hitachi | Ucosminexus Client | 06_70_06_70_b |
| Hitachi | Ucosminexus Client | 06_71_06_71_b |
| Hitachi | Ucosminexus Client | 07_00_07_20 |
| Hitachi | Ucosminexus Developer | 06_70_06_70_b |
| Hitachi | Ucosminexus Developer | 06_71_06_71_b |
| Hitachi | Ucosminexus Operator | 07_00_07_20 |
| Hitachi | Ucosminexus Service Architect | 07_00_07_20 |
| Hitachi | Ucosminexus Service Platform | 07_00_07_20 |
| Hitachi | Cosminexus Application Server | 05_05_05_05_h |
| Hitachi | Cosminexus Application Server | 06_00_06_00_b |
| Hitachi | Cosminexus Application Server | 06_00_06_00_d |
| Hitachi | Cosminexus Application Server | 06_50_06_50_b |
| Hitachi | Cosminexus Application Server | 06_50_06_50_c |
| Hitachi | Cosminexus Application Server | 06_51_06_51_b |
| Hitachi | Cosminexus Application Server | 06_51_06_51_c |
| Hitachi | Ucosminexus Application Server | 07_00_07_10 |
| Hitachi | Ucosminexus Service Platform | 07_00_07_10 |
| Hitachi | Cosminexus Application Server | 05_02_05_02_e |
| Hitachi | Cosminexus Application Server | 06_00_06_00_e |
| Hitachi | Cosminexus Application Server | 06_50_06_50_d |
| Hitachi | Ucosminexus Application Server | 06_70_06_70_h |
| Hitachi | Ucosminexus Application Server | 06_70_06_72 |
| Hitachi | Ucosminexus Application Server | 07_10 |
Showing 50 of 58 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/26025Vendor Advisory
- http://secunia.com/advisories/26025Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3794?
How severe is CVE-2007-3794?
How do I fix CVE-2007-3794?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-3788The eSoft InstaGate EX2 UTM device stores the admin password…
- CVE-2007-3789SQL injection vulnerability in admin/index.php in Inmostore …
- CVE-2007-3790The com_print_typeinfo function in the bz2 extension in PHP …
- CVE-2007-3791Buffer overflow in the w_read function in sockets.c in Cami …
- CVE-2007-3792Multiple PHP remote file inclusion vulnerabilities in AzDG D…
- CVE-2007-3793SQL injection vulnerability in Job Management Partner 1/NETM…
- CVE-2007-3795Unspecified vulnerability in Hitachi TP1/Server Base before …
- CVE-2007-3796The password reset feature in the Spam Quarantine HTTP inter…
- CVE-2007-3798Integer overflow in print-bgp.c in the BGP dissector in tcpd…9.8
- CVE-2007-3799The session_start function in ext/session in PHP 4.x up to 4…
- CVE-2007-3800Unspecified vulnerability in the Real-time scanner (RTVScan)…
- CVE-2007-3801Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
Are you affected by CVE-2007-3794?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
