peter bassill · operator
$ cve CVE-2007-6189 JSON

CVE-2007-6189 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 8.1% (pctl 95)

Patch early

A public exploit exists.

Description

A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%%" sequence, which is misinterpreted as a Unicode string and decoded twice, leading to improper memory allocation and a heap-based buffer overflow.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS8.08% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-11-30
Last modified2026-06-16

Affected (1)

VendorProduct
bitdefenderonline anti-virus scanner

Public exploits

SourceTitleDate
exploit-dbBitDefender Online Scanner 8 - ActiveX Heap Overflow2007-11-27

References

→ the Explorer  ·  watch your stack  ·  NVD