CVE-2007-3169

Edraw Office Viewer Component < 5.0 - Memory Corruption

Title source: rule

Description

Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long first argument to the HttpDownloadFile method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · htmldoswindows
https://www.exploit-db.com/exploits/4009

Scores

EPSS 0.3215
EPSS Percentile 96.8%

Details

CWE
CWE-119
Status published
Products (2)
edraw/office_viewer_component 4.0.5.20
edraw/office_viewer_component < 5.0
Published Jun 11, 2007
Tracked Since Feb 18, 2026