peter bassill · operator
$ cve CVE-2007-3336 JSON

CVE-2007-3336 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 9% (pctl 95)

Patch early

A public exploit exists.

Description

Multiple "pointer overwrite" vulnerabilities in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (formerly Computer Associates) products, allow remote attackers to execute arbitrary code by sending certain TCP data at different times to the Ingres Communications Server Process (iigcc), which calls the (1) QUinsert or (2) QUremove functions with attacker-controlled input.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS8.96% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2007-06-22
Last modified2026-06-16

Affected (1)

VendorProduct
ingresdatabase server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD