CVE-2007-1770 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 16.8% (pctl 97)
Patch early
A public exploit exists.
Description
Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 16.84% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-120 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-03-30 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| esri | arcsde |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ESRI ArcSDE 9.0 < 9.2sp1 - Remote Buffer Overflow | 2007-07-03 |
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=507
- http://secunia.com/advisories/24639
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1260
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1261
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1262
- http://www.securityfocus.com/bid/23175
- http://www.securitytracker.com/id?1017874
- http://www.vupen.com/english/advisories/2007/1140
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33282
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33457
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=507
- http://secunia.com/advisories/24639
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1260
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1261
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=19&MetaID=1262
- http://www.securityfocus.com/bid/23175
- http://www.securitytracker.com/id?1017874
- http://www.vupen.com/english/advisories/2007/1140
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33282
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33457
→ the Explorer · watch your stack · NVD