peter bassill · operator
$ cve CVE-2007-1770 JSON

CVE-2007-1770 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 16.8% (pctl 97)

Patch early

A public exploit exists.

Description

Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS16.84% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploityes
Published2007-03-30
Last modified2026-06-16

Affected (1)

VendorProduct
esriarcsde

Public exploits

SourceTitleDate
exploit-dbESRI ArcSDE 9.0 < 9.2sp1 - Remote Buffer Overflow2007-07-03

References

→ the Explorer  ·  watch your stack  ·  NVD