Security Advisory

CVE-2007-3675

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2007-10-12 20:00:00
Last updated 2024-08-07 14:28:51
Assigner mitre
State PUBLISHED

Description

Multiple format string vulnerabilities in the kavwebscan.CKAVWebScan ActiveX control (kavwebscan.dll) in Kaspersky Online Scanner before 5.0.98 allow remote attackers to execute arbitrary code via format string specifiers in "various string formatting functions," which trigger heap-based buffer overflows.