peter bassill · operator
$ cve CVE-2007-5604 JSON

CVE-2007-5604 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 11.7% (pctl 96)

Patch early

A public exploit exists.

Description

Buffer overflow in the ExtractCab function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5605, CVE-2007-5606, and CVE-2007-5607.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS11.67% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2008-06-04
Last modified2026-06-16

Affected (1)

VendorProduct
hpinstant support

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD