CVE-2007-4547
Last modified
CVE-2007-4547 is a vulnerability of currently unknown severity. Unreal Commander 0.92 build 565 and 573 writes portions of heap memory into local files when extracting from an archive with malformed size information in a file header, which might allow user-assisted attackers to obtain sensitive information (memory contents) by reading the extracted files. NOTE: this issue is only a vulnerability if Unreal is run with privileges, or if the extracted files are made accessible to other users.. EPSS estimates a 1.27% chance of exploitation in the next 30 days.
Description
Unreal Commander 0.92 build 565 and 573 writes portions of heap memory into local files when extracting from an archive with malformed size information in a file header, which might allow user-assisted attackers to obtain sensitive information (memory contents) by reading the extracted files. NOTE: this issue is only a vulnerability if Unreal is run with privileges, or if the extracted files are made accessible to other users.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| X-Diesel | Unreal Commander | 0.92_build565 |
| X-Diesel | Unreal Commander | 0.92_build573 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4547?
How severe is CVE-2007-4547?
How do I fix CVE-2007-4547?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4541Multiple cross-site scripting (XSS) vulnerabilities in Olate…
- CVE-2007-4542Multiple cross-site scripting (XSS) vulnerabilities in MapSe…
- CVE-2007-4543Cross-site scripting (XSS) vulnerability in enter_bug.cgi in…
- CVE-2007-4544Cross-site scripting (XSS) vulnerability in wp-newblog.php i…
- CVE-2007-4545Multiple directory traversal vulnerabilities in Unreal Comma…
- CVE-2007-4546Unreal Commander 0.92 build 565 and 573 lists the filenames …
- CVE-2007-4548The login method in LoginModule implementations in Apache Ge…
- CVE-2007-4549Multiple buffer overflows in ALPass 2.7 English and 3.02 Kor…
- CVE-2007-4550Format string vulnerability in ALPass 2.7 English and 3.02 K…
- CVE-2007-4551PHP remote file inclusion vulnerability in index.php in Agar…
- CVE-2007-4552SQL injection vulnerability in index.php in Agares Media Arc…
- CVE-2007-4553The Thomson ST 2030 SIP phone with software 1.52.1 allows re…
Are you affected by CVE-2007-4547?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
