Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2007-0025

EPSS 73.92% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-0025

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft Windows MFC组件OLE对象缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。 Microsoft Windows 2000 SP4,XP SP2,2003 SP1版本,Visual Studio .NET 2000,2002 SP1,2003以及2003 SP1版本中的MFC组件中存在缓冲区溢出漏洞。用户辅助的远程攻击者可借助带有畸形OLE对象的RTF文件执行任意代码,该对象可触发内存破坏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-0025

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-0025

登录查看更多情报信息。

Vendor Advisories for CVE-2007-0025 (8)

Same Patch Batch · n/a · 2007-02-13 · 29 CVEs total

CVE-2006-3448Microsoft Windows分步交互式训练缓冲区溢出漏洞
CVE-2007-0895Solaris 竞争条件权限管理和访问控制漏洞
CVE-2007-0896Firefox多个跨站脚本攻击漏洞
CVE-2007-0842Microsoft Visual C++标准库时间函数拒绝服务漏洞
CVE-2007-0904LightRO CMS 'projects.php'SQL注入漏洞
CVE-2007-0903EJabberD Mod_Roster_ODBC 未明漏洞
CVE-2007-0902MoinMoin "展示调试信息"特征未明信息泄露漏洞
CVE-2007-0901MoinMoin Info页多个跨站脚本攻击漏洞
CVE-2007-0900TagIt! Tagboard 多个PHP远程文件包含漏洞
CVE-2007-0214Microsoft HTML帮助ActiveX控件远程代码执行漏洞(MS07-008)
CVE-2007-0211Microsoft Windows Shell硬件检测服务权限提升漏洞(MS07-006)
CVE-2007-0210Microsoft Windows图像捕获服务本地权限提升漏洞(MS07-007)
CVE-2007-0026Microsoft Windows OLE Dialog内存破坏漏洞(MS07-011)
CVE-2006-5270Microsoft恶意软件保护引擎整数溢出漏洞(MS07-010)
CVE-2007-0219Microsoft Internet Explorer 安全漏洞
CVE-2006-1311Microsoft Office和Windows RichEdit组件内存破坏漏洞(MS07-013)
CVE-2007-0209Microsoft Word畸形绘图对象任意代码执行漏洞(MS07-014)
CVE-2007-0208Microsoft Word宏权限绕过任意代码执行漏洞(MS07-014)
CVE-2007-0217Microsoft Internet Explorer 安全漏洞
CVE-2006-4697Microsoft Internet Explorer 安全漏洞

Showing top 20 of 29 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-0025

No comments yet


Leave a comment