peter bassill · operator
$ cve CVE-2007-5911 JSON

CVE-2007-5911 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 4% (pctl 90)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in the AxMetaStream ActiveX control in AxMetaStream.dll 3.3.2.26 in Viewpoint Media Player 3.2 allow remote attackers to execute arbitrary code via a long string argument to the (1) BroadcastKey, (2) BroadcastKeyFileURL, (3) Component, (4) ComponentClassID, (5) ComponentFileName, (6) ExtraProperty, (7) Properties, (8) RequiredVersions, (9) Source, or (10) XMLText method.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS4.01% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-11-10
Last modified2026-06-16

Affected (1)

VendorProduct
viewpointmedia player

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD