CVE-2007-2494
Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) Save, (6) SaveWebFile, (7) HttpDownloadFile, (8) Open, or (9) OpenWebFile property value. NOTE: some of these details are obtained from third party information.
- Affected products
- Internet Explorer 7, Powerpointviewer.Ocx
- Office Ocx Powerpoint Viewer Ocx
- ≤ 3.1.0.3
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 5.2% (92th percentile)
- NVD status
- Modified
- Published
- 2007-05-04
CVE-2007-2494 at NVD
1 known exploit for CVE-2007-2494
Proof-of-concept code and exploit modules indexed by Sploitus