peter bassill · operator
$ cve CVE-2007-2814 JSON

CVE-2007-2814 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 5.5% (pctl 93)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in the Pegasus ImagN' ActiveX control (IMW32O40.OCX) 4.00.041 allow remote attackers to execute arbitrary code via (1) a long FileName parameter, or unspecified vectors involving the (2) BeginReport, (3) CreatePictureExA, (4) DefineImage, (5) DefineImageEx, (6) DefineImageFox, (7) CopyBufToClipExA, (8) LoadEx, (9) LoadFox, and other functions.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS5.48% — more likely to be exploited than 93% of all CVEs
On CISA KEVno
Public exploityes
Published2007-05-22
Last modified2026-06-16

Affected (1)

VendorProduct
pegasusimagn activex control

Public exploits

SourceTitleDate
exploit-dbPegasus ImagN - ActiveX Control Remote Buffer Overflow2007-05-21

References

→ the Explorer  ·  watch your stack  ·  NVD