Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2007-0025
StatusCandidate
DescriptionThe MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the the AfxOleSetEditMenu function in MFC42u.dll.
SeverityHigh
CVSS score9,3
CVSS vector(AV:N/AC:M/Au:N/C:C/I:C/A:C)
PhaseAssigned (20.06.2011)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0025
ReferencesBID : 22476
 CERT-VN : VU#932041
 FRSIRT : ADV-2007-0581
 MS : MS07-012
 OSVDB : 31887
 SECTRACK : 1017638
 SECUNIA : 24150
SecurityVulns:Microsoft MFC memory corruption

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server