Record summary

CVE-2007-4802 has a selected CVSS score of 6.8; EIP currently links 2 catalogued exploits.

Description

Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a long eighth argument to the SetInfo method in a certain ActiveX control in glItemCom.dll or (2) a long second argument to the SetClientInfo method in a certain ActiveX control in glitemflat.dll.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBGlobalLink 2.7.0.8 - 'glItemCom.dll SetInfo()' Heap OverflowExploitDB exploitby voidNot analyzed1 file
ExploitDB

PoC details
ExploitDBGlobalLink 2.7.0.8 - 'glitemflat.dll SetClientInfo()' Heap OverflowExploitDB exploitby voidNot analyzed1 file
ExploitDB

PoC details

References

9