CVE-2007-5910
published 2007-11-10CVE-2007-5910: Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.62%
93.1th percentile
Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect (WPD) file.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activepdf | docconverter | — | — |
| autonomy | keyview_export_sdk | <= 9.2.0 | — |
| autonomy | keyview_filter_sdk | <= 9.2.0 | — |
| autonomy | keyview_viewer_sdk | <= 9.2.0 | — |
| ibm | lotus_notes | <= 7.0.2 | — |
| symantec | mail_security | — | — |
| symantec | mail_security | — | — |
| symantec | mail_security | — | — |
| symantec | mail_security | — | — |
| symantec | mail_security | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5m3m-cp9q-wr3m: Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2007-5909 [CRITICAL] CWE-119 GHSA-5m3m-cp9q-wr3m: Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910.
GHSA
GHSA-p542-8xvj-878h: Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9
ghsa_unreviewed·2022-05-01
CVE-2007-5910 [HIGH] CWE-119 GHSA-p542-8xvj-878h: Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9
Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect (WPD) file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/27304http://securityreason.com/securityalert/3357http://securityresponse.symantec.com/avcenter/security/Content/2007.11.01c.htmlhttp://securitytracker.com/id?1018853http://securitytracker.com/id?1018886http://vuln.sg/lotusnotes702-en.htmlhttp://vuln.sg/lotusnotes702wpd-en.htmlhttp://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21271111http://www.securityfocus.com/archive/1/482664http://www.securityfocus.com/bid/26175http://www.vupen.com/english/advisories/2007/3596http://www.vupen.com/english/advisories/2007/3697http://secunia.com/advisories/27304http://securityreason.com/securityalert/3357http://securityresponse.symantec.com/avcenter/security/Content/2007.11.01c.htmlhttp://securitytracker.com/id?1018853http://securitytracker.com/id?1018886http://vuln.sg/lotusnotes702-en.htmlhttp://vuln.sg/lotusnotes702wpd-en.htmlhttp://www-1.ibm.com/support/docview.wss?rs=899&uid=swg21271111http://www.securityfocus.com/archive/1/482664http://www.securityfocus.com/bid/26175http://www.vupen.com/english/advisories/2007/3596http://www.vupen.com/english/advisories/2007/3697
2007-11-10
Published