CVE-2007-0065

CWE-94Code Injection5 documents5 sources
Severity
10.0CRITICAL
EPSS
61.9%
top 1.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 12
Latest updateMay 1

Description

Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-cxhf-96w9-6fjf: Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Off2022-05-01
CVEList
CVE-2007-0065: Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Off2008-02-12

💥Exploits & PoCs

1
Exploit-DB
Microsoft Office 2007 - OneTableDocumentStream Invalid Object2015-08-25

💬Community

1
Bugzilla
CVE-2006-6899 Bluetooth HID key events injection flaw2007-02-02
CVE-2007-0065 (CRITICAL CVSS 10) | Heap-based buffer overflow in Objec | cvebase.io