CVE-2007-5257
Last modified
CVE-2007-5257 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169.. EPSS estimates a 15.22% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Edraw | Office Viewer Component | <= 5.3.220.1 |
References
- http://secunia.com/advisories/27017Vendor Advisory
- http://secunia.com/advisories/27017Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5257?
How severe is CVE-2007-5257?
How do I fix CVE-2007-5257?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5251Multiple cross-site scripting (XSS) vulnerabilities in Helm …
- CVE-2007-5252Buffer overflow in NetSupport Manager (NSM) Client 10.00 and…
- CVE-2007-5253c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows re…
- CVE-2007-5254VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (E…
- CVE-2007-5255Cross-site scripting (XSS) vulnerability in Google Mini Sear…
- CVE-2007-5256Multiple stack-based buffer overflows in FSD 2.052 d9 and ea…
- CVE-2007-5258PHP remote file inclusion vulnerability in log.php in phpFre…
- CVE-2007-5259Cross-site request forgery (CSRF) vulnerability in Ilient Sy…
- CVE-2007-5260ASP-CMS 1.0 stores sensitive information under the web root …
- CVE-2007-5261Multiple SQL injection vulnerabilities in MultiCart 1.0 allo…
- CVE-2007-5262Multiple format string vulnerabilities in Battlefront Dropte…
- CVE-2007-5263Multiple buffer overflows in Battlefront Dropteam 1.3.3 and …
Are you affected by CVE-2007-5257?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
