CVE-2007-5257 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 15.2% (pctl 97)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 15.22% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-10-06 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| edraw | office viewer component |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | EDraw Office Viewer Component 5.3 - 'FtpDownloadFile()' Remote Buffer Overflow | 2007-10-01 |
References
- http://osvdb.org/37724
- http://secunia.com/advisories/27017
- http://shinnai.altervista.org/exploits/txt/TXT_O5FvsIzILBHQr7QbK2kD.html
- http://www.securityfocus.com/bid/25892
- http://www.vupen.com/english/advisories/2007/3329
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36879
- https://www.exploit-db.com/exploits/4474
- http://osvdb.org/37724
- http://secunia.com/advisories/27017
- http://shinnai.altervista.org/exploits/txt/TXT_O5FvsIzILBHQr7QbK2kD.html
- http://www.securityfocus.com/bid/25892
- http://www.vupen.com/english/advisories/2007/3329
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36879
- https://www.exploit-db.com/exploits/4474
→ the Explorer · watch your stack · NVD