CVE-2007-3675

Kaspersky Online Scanner < 5.0.93 - Remote Code Execution via Format String Vulnerability

Title source: llm
STIX 2.1

Description

Multiple format string vulnerabilities in the kavwebscan.CKAVWebScan ActiveX control (kavwebscan.dll) in Kaspersky Online Scanner before 5.0.98 allow remote attackers to execute arbitrary code via format string specifiers in "various string formatting functions," which trigger heap-based buffer overflows.

References (7)

Core 7
Core References
Patch x_refsource_confirm
http://www.kaspersky.com/news?id=207575572
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1018800
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/37057
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27187
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=606
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26004
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3455

Scores

EPSS 0.0481
EPSS Percentile 90.8%

Details

CWE
CWE-134
Status published
Products (1)
kaspersky_lab/online_scanner < 5.0.93
Published Oct 12, 2007
Tracked Since Feb 18, 2026