CVE-2017-7310
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element.
- Affected products
- Diskboss, Diskpulse, Disksavvy, Disksorter, Dupscout, Syncbreeze, Vx Search
- Flexense Diskboss
- = 7.8.16
- Flexense Disksorter
- = 9.5.12
- Flexense Syncbreeze
- = 9.5.16
- Fix
- Available
- CVSS 3.0
- 7.8 HIGH
- EPSS
- 53.7% (99th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2017-03-29
CVE-2017-7310 at NVD
11 known exploits for CVE-2017-7310
Proof-of-concept code and exploit modules indexed by Sploitus
Disk Pulse Enterprise 10.4.18 Buffer Overflow
Disk Pulse Enterprise 10.4.18 - Import Command Buffer Overflow (SEH) Exploit
Disk Pulse Enterprise 10.4.18 - Import Command Buffer Overflow (SEH)
Disk Pulse Enterprise 10.4.18 - 'Import Command' Buffer Overflow (SEH)
Dup Scout Enterprise 10.4.16 Import Command Buffer Overflow
Sync Breeze Enterprise 9.5.16 - Import Command Buffer Overflow Exploit
Sync Breeze Enterprise 9.5.16 - 'Import Command' Buffer Overflow (Metasploit)
Sync Breeze Enterprise 9.5.16 Import Command Buffer Overflow
Dup Scout Enterprise v10.4.16 - Import Command Buffer Overflow
Sync Breeze Enterprise 9.5.16 - Import Command Buffer Overflow
Sync Breeze Enterprise 9.5.16 - 'Import Command' Local Buffer Overflow