peter bassill · operator
$ cve CVE-2007-4916 JSON

CVE-2007-4916 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 19.7% (pctl 97)

Patch early

A public exploit exists.

Description

Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS19.67% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-09-17
Last modified2026-06-16

Affected (2)

VendorProduct
hpall-in-on printer
hpphoto and imaging gallery

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD