CVE-2007-5779 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 71.5% (pctl 99)
Patch early
A public exploit exists.
Description
Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Player (GOM Player) 2.1.6.3499 allows remote attackers to execute arbitrary code via a long argument to the OpenUrl method.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 71.51% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-11-01 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| gom player | gom player |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GOM Player - ActiveX Control Buffer Overflow (Metasploit) | 2010-05-09 |
| exploit-db | GOM Player 2.1.6.3499 - 'GomWeb3.dll 1.0.0.12' Remote Overflow | 2007-10-29 |
References
- http://secunia.com/advisories/27418
- http://www.gomplayer.com/forum/viewtopic.html?t=1013
- http://www.securityfocus.com/bid/26236
- http://www.vupen.com/english/advisories/2007/3634
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38159
- https://www.exploit-db.com/exploits/4579
- http://secunia.com/advisories/27418
- http://www.gomplayer.com/forum/viewtopic.html?t=1013
- http://www.securityfocus.com/bid/26236
- http://www.vupen.com/english/advisories/2007/3634
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38159
- https://www.exploit-db.com/exploits/4579
→ the Explorer · watch your stack · NVD