VDB
CVE-2007-2239
CVE-2007-2239
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 2400, 2400+, 2401, 2401+, 2411, and Panorama PTZ allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long argument.
EPSS 27.40% · 96.5th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
27.40%
96.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| axis | 2100_network_camera | 0 |
| axis | 2401_video_server | 0 |
| axis | 2110_network_camera | 0 |
| axis | 2420_network_camera | 0 |
| axis | 2411_video_server | 0 |
| axis | 2130_ptz_network_camera | 0 |
| axis | 2400_video_server | 0 |
| axis | 2120_network_camera | 0 |
| n/a | n/a | n/a |
| axis | 2420-ir_network_camera | 0 |
| axis | panorama_ptz_camera | 0 |
Timeline
- May 4, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 9, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- axis-activex-savebmp-bo(34133) vdb
- 35602 vdb
- ADV-2007-1663 vdb
- http://www.axis.com/techsup/software/acc/files/acc_security_update_1_00.pdf url
- 23816 vdb
- VU#355809 third-party-advisory
- 25093 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-2239 advisory