CVE-2007-2239
published 2007-05-07CVE-2007-2239: Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100…
PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
11.81%
95.6th percentile
Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 2400, 2400+, 2401, 2401+, 2411, and Panorama PTZ allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long argument.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axis | 2100_network_camera | <= 2.39 | — |
| axis | 2110_network_camera | <= 2.39 | — |
| axis | 2120_network_camera | <= 2.39 | — |
| axis | 2130_ptz_network_camera | <= 2.39 | — |
| axis | 2400_video_server | <= 2.39 | — |
| axis | 2401_video_server | <= 2.39 | — |
| axis | 2411_video_server | <= 2.39 | — |
| axis | 2420-ir_network_camera | <= 2.39 | — |
| axis | 2420_network_camera | <= 2.39 | — |
| axis | panorama_ptz_camera | <= 2.39 | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://osvdb.org/35602http://secunia.com/advisories/25093http://www.axis.com/techsup/software/acc/files/acc_security_update_1_00.pdfhttp://www.kb.cert.org/vuls/id/355809http://www.securityfocus.com/bid/23816http://www.vupen.com/english/advisories/2007/1663https://exchange.xforce.ibmcloud.com/vulnerabilities/34133http://osvdb.org/35602http://secunia.com/advisories/25093http://www.axis.com/techsup/software/acc/files/acc_security_update_1_00.pdfhttp://www.kb.cert.org/vuls/id/355809http://www.securityfocus.com/bid/23816http://www.vupen.com/english/advisories/2007/1663https://exchange.xforce.ibmcloud.com/vulnerabilities/34133
2007-05-07
Published