peter bassill · operator
$ cve CVE-2007-1682 JSON

CVE-2007-1682 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 29.6% (pctl 98)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists, or (4) DeleteFile method.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS29.61% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2008-08-27
Last modified2026-06-16

Affected (1)

VendorProduct
softartisansxfile

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD