CVE-2007-3955

LinkedIn Toolbar 3.0.2.1098 - Buffer Overflow via IEContextMenu search Method

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3955. PoCs published by Jared DeMott.

AI-analyzed exploit summary This exploit targets a heap overflow vulnerability in the VDA Labs ActiveX control (clsid:0F2437D6-C4E4-42CA-A906-F506E09354B7) by triggering a buffer overflow via the 'search' method. It uses a combination of NOP sleds and shellcode to achieve remote code execution.

Description

Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a long second argument (varBrowser argument) to the search method. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jared DeMott · htmlremotewindows
https://www.exploit-db.com/exploits/4217

This exploit targets a heap overflow vulnerability in the VDA Labs ActiveX control (clsid:0F2437D6-C4E4-42CA-A906-F506E09354B7) by triggering a buffer overflow via the 'search' method. It uses a combination of NOP sleds and shellcode to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VDA Labs ActiveX control
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · VDA Labs ActiveX control must be installed and enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Various Sources x_refsource_misc
http://www.vdalabs.com/tools/linkedin.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37696
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35578
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26181
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25032
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4217
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2620

Scores

EPSS 0.0824
EPSS Percentile 94.2%

Details

Status published
Products (1)
linkedin/toolbar 3.0.2.1098
Published Jul 24, 2007
Tracked Since Feb 18, 2026