CVE-2007-5756
Last modified
CVE-2007-5756 is a vulnerability of currently unknown severity. Multiple array index errors in the bpf_filter_init function in NPF.SYS in WinPcap before 4.0.2, when run in monitor mode (aka Table Management Extensions or TME), and as used in Wireshark and possibly other products, allow local users to gain privileges via crafted IOCTL requests.. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Multiple array index errors in the bpf_filter_init function in NPF.SYS in WinPcap before 4.0.2, when run in monitor mode (aka Table Management Extensions or TME), and as used in Wireshark and possibly other products, allow local users to gain privileges via crafted IOCTL requests.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Winpcap | Winpcap | < 4.0.2 |
References
- http://secunia.com/advisories/27676Broken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/26409Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018935Broken Link, Third Party Advisory, VDB Entry
- http://www.winpcap.org/misc/changelog.htmRelease Notes
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38433Third Party Advisory, VDB Entry
- http://secunia.com/advisories/27676Broken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/26409Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018935Broken Link, Third Party Advisory, VDB Entry
- http://www.winpcap.org/misc/changelog.htmRelease Notes
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38433Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5756?
How severe is CVE-2007-5756?
How do I fix CVE-2007-5756?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5747Integer underflow in OpenOffice.org before 2.4 allows remote…
- CVE-2007-5751Liferea before 1.4.6 uses weak permissions (0644) for the fe…
- CVE-2007-5752adduser.php in PHP-AGTC Membership (AGTC-Membership) System …
- CVE-2007-5753Unspecified vulnerability in Light FMan PHP (lfman or lightf…
- CVE-2007-5754PHP remote file inclusion vulnerability in urlinn_includes/c…
- CVE-2007-5755Multiple stack-based buffer overflows in the AOL AmpX Active…
- CVE-2007-5757Untrusted search path vulnerability in db2pd in IBM DB2 Univ…
- CVE-2007-5758Stack-based buffer overflow in db2dasrrm in the DB2 Administ…
- CVE-2007-5759Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2007-5760Array index error in the XFree86-Misc extension in X.Org Xse…
- CVE-2007-5761The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 bu…
- CVE-2007-5762NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.…
Are you affected by CVE-2007-5756?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
