peter bassill · operator
$ cve CVE-2007-2864 JSON

CVE-2007-2864 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 49.6% (pctl 99)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS49.65% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2007-06-06
Last modified2026-06-16

Affected (13)

VendorProduct
broadcomanti-virus for the enterprise
broadcombrightstor arcserve backup
broadcomcommon services
broadcometrust antivirus
broadcometrust antivirus gateway
broadcometrust antivirus sdk
broadcometrust ez antivirus
broadcometrust ez armor
broadcomintegrated threat management
broadcominternet security suite
broadcomunicenter network and systems management
caetrust secure content manager
caprotection suites

Public exploits

SourceTitleDate
exploit-dbCA AntiVirus Engine - CAB Buffer Overflow (Metasploit)2010-11-11

References

→ the Explorer  ·  watch your stack  ·  NVD