CVE-2017-7310
Last modified
CVE-2017-7310 is a vulnerability of currently unknown severity. A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element.. EPSS estimates a 66.81% chance of exploitation in the next 30 days.
Description
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Flexense | Diskboss | 7.8.16 |
| Flexense | Disksorter | 9.5.12 |
| Flexense | Syncbreeze | 9.5.16 |
References
- http://www.securityfocus.com/bid/97237Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41771/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41772/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41773/Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/97237Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41771/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41772/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41773/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7310?
How severe is CVE-2017-7310?
How do I fix CVE-2017-7310?
Are you affected by CVE-2017-7310?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
