Vulnerabilities > CVE-2007-2494 - Denial of Service vulnerability in Office OCX PowerPoint Viewer ActiveX

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
office-ocx
critical
exploit available

Summary

Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) Save, (6) SaveWebFile, (7) HttpDownloadFile, (8) Open, or (9) OpenWebFile property value. NOTE: some of these details are obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Office_Ocx
1

Exploit-Db

descriptionPowerPoint Viewer OCX 3.2 (ActiveX Control) Denial of Service Exploit. CVE-2007-2494. Dos exploit for windows platform
fileexploits/windows/dos/3826.html
idEDB-ID:3826
last seen2016-01-31
modified2007-05-01
platformwindows
port
published2007-05-01
reportershinnai
sourcehttps://www.exploit-db.com/download/3826/
titlePowerPoint Viewer OCX 3.2 ActiveX Control Denial of Service Exploit
typedos