Vulnerability Description
Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute arbitrary code via a long DriverName property.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lead Technologies | Leadtools Isis Activex Control | <= 14.5.0.44 |
Related Weaknesses (CWE)
References
- http://moaxb.blogspot.com/2007/05/moaxb-22-leadtools-isis-control.html
- http://osvdb.org/36032
- http://secunia.com/advisories/25349Vendor Advisory
- http://www.securityfocus.com/bid/24093
- http://www.shinnai.altervista.org/moaxb/20070522/leadisistxt.html
- http://www.vupen.com/english/advisories/2007/1900Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34437
- http://moaxb.blogspot.com/2007/05/moaxb-22-leadtools-isis-control.html
- http://osvdb.org/36032
- http://secunia.com/advisories/25349Vendor Advisory
- http://www.securityfocus.com/bid/24093
- http://www.shinnai.altervista.org/moaxb/20070522/leadisistxt.html
- http://www.vupen.com/english/advisories/2007/1900Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34437
FAQ
What is CVE-2007-2827?
CVE-2007-2827 is a vulnerability with a CVSS score of 9.3 (HIGH). Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute arbitrary code via a long DriverName property.
How severe is CVE-2007-2827?
CVE-2007-2827 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2827?
Check the references section above for vendor advisories and patch information. Affected products include: Lead Technologies Leadtools Isis Activex Control.