peter bassill · operator
$ cve CVE-2007-5257 JSON

CVE-2007-5257 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 15.2% (pctl 97)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS15.22% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-10-06
Last modified2026-06-16

Affected (1)

VendorProduct
edrawoffice viewer component

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD