Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-3897

EPSS 64.04% · P98
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-3897

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft Outlook Express和Windows Mail NNTP协议回应数据缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Outlook Express和Windows Mail都是Windows操作系统所捆绑的邮件和新闻组客户端。NNTP(网络新闻传输协议)是用于读取和张贴Usenet文章的协议。 Windows Mail和Outlook Express在处理NNTP回复时存在堆溢出漏洞,恶意NNTP服务器可能利用此漏洞控制用户系统。 如果服务器返回了多于客户端所请求的数据,就可能将攻击者可控的值储存到所分配的内存范围之外,覆盖控制结构,导致执行任意指令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-3897

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-3897

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-10-09 · 63 CVEs total

CVE-2007-5307ELSEIF CMS 'upload.php' alphanumeric参数多个输入验证漏洞
CVE-2007-3893Microsoft Internet Explorer资源管理错误漏洞
CVE-2007-5319Sun Solaris vuidmice STREAMS模数未明拒绝服务漏洞
CVE-2007-4466Electronic Arts SnoopyCtrl ActiveX控件'NPSnpy.dll' 多个缓冲区溢出漏洞
CVE-2007-3899Microsoft Word工作区内存破坏远程代码执行漏洞
CVE-2007-5312TorrentTrader Classic cat参数多个跨站脚本攻击漏洞
CVE-2007-5311TorrentTrader Classic Edition 'backend/admin-functions.php' 目录遍历漏洞
CVE-2007-5310Joomla! Webmaster-Tips.net 'admin.wmtportfolio.php' 远程文件包含漏洞
CVE-2007-5309Joomla! Webmaster-Tips.net Flash Image Gallery 'admin.wmtgallery.php' 远程文件包含漏洞
CVE-2007-5308PHP Homepage M 'galerie.php' SQL注入漏洞
CVE-2007-5313Picturesolution 'Config.PHP' 远程文件包含漏洞
CVE-2007-5306ELSEIF CMS 'votesresultats.php' 多个输入验证漏洞
CVE-2007-5305Else If CMS 多个PHP远程文件包含漏洞
CVE-2007-5304ELSEIF CMS 跨站脚本攻击漏洞
CVE-2007-5303SnewsCMS Rus 'news_page.php' 跨站脚本攻击漏洞
CVE-2007-5302HP System Management Homepage (SMH) for Linux, Windows, and HP-UX 多个跨站脚本攻击漏洞
CVE-2007-5301AlsaPlayer Vorbis输入插件OGG文件处理远程缓冲区溢出漏洞
CVE-2007-5300wzdftpd USER指令远程拒绝服务漏洞
CVE-2007-5299SkaDate Online Dating Software 'member/' 多个目录遍历漏洞
CVE-2007-5298CMS Creamotion 多个PHP远程文件包含漏洞代码注入漏洞

Showing top 20 of 63 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-3897

No comments yet


Leave a comment