peter bassill · operator
$ cve CVE-2007-4336 JSON

CVE-2007-4336 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 50.7% (pctl 99)

Patch early

A public exploit exists.

Description

Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX control in DXTLIPI.DLL 6.0.2.827, as packaged in Microsoft DirectX Media 6.0 SDK, allows remote attackers to execute arbitrary code via a long SourceUrl property value.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS50.71% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2007-08-14
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftdirectx media

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD