peter bassill · operator
$ cve CVE-2007-2496 JSON

CVE-2007-2496 EXPLOIT

7.8
HIGH · CVSS 2.0 · EPSS 3.8% (pctl 90)

Patch early

A public exploit exists.

Description

The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value.

Scoring

CVSS7.8 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS3.83% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploityes
Published2007-05-04
Last modified2026-06-16

Affected (1)

VendorProduct
office ocxword viewer ocx

Public exploits

SourceTitleDate
exploit-dbWord Viewer OCX 3.2 - Remote Denial of Service2007-05-03

References

→ the Explorer  ·  watch your stack  ·  NVD