CVE-2007-2919 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 33.7% (pctl 98)
Patch early
A public exploit exists.
Description
Multiple stack-based buffer overflows in the FViewerLoading ActiveX control (FlipViewerX.dll) in E-Book Systems FlipViewer before 4.1 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via long (1) UID, (2) Opf, (3) PAGENO, (4) LaunchMode, (5) SubID, (6) BookID, (7) LibraryID, (8) SubURL, and (9) LoadOpf properties.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 33.72% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-06-06 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| e-book systems | flipviewer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | FlipViewer FViewerLoading - ActiveX Control Buffer Overflow (Metasploit) | 2010-06-15 |
References
- http://osvdb.org/37042
- http://secunia.com/advisories/25568
- http://www.kb.cert.org/vuls/id/449089
- http://www.securityfocus.com/bid/24328
- http://www.vupen.com/english/advisories/2007/2081
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34742
- http://osvdb.org/37042
- http://secunia.com/advisories/25568
- http://www.kb.cert.org/vuls/id/449089
- http://www.securityfocus.com/bid/24328
- http://www.vupen.com/english/advisories/2007/2081
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34742
→ the Explorer · watch your stack · NVD