CVE-2007-0111
Summary
| CVE | CVE-2007-0111 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-01-09 00:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Buffer overflow in Resco Photo Viewer for PocketPC 4.11 and 6.01, as used in mobile devices running Windows Mobile 5.0, 2003, and 2003SE, allows remote attackers to execute arbitrary code via a crafted PNG image. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Resco | Photo Viewer | 4.11 | All | All | All |
| Application | Resco | Photo Viewer | 6.11 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Resco Photo Viewer for PocketPC Malformed PNG File Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| Flaw in 3rd-party App Weakens Windows Mobile | TrendLabs | Malware Blog - by Trend Micro | af854a3a-2127-422b-91ae-364da2661108 | blog.trendmicro.com | Vendor Advisory |
| osvdb.org/32644 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Resco Photo Viewer PNG Handling Unspecified Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Vulnerability in Resco Photo Viewer 6.01 Enabling Code Injection and Arbitrary Code Execution | af854a3a-2127-422b-91ae-364da2661108 | www.trendmicro.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Vulnerability in Resco Photo Viewer 6.01 Enabling Code Injection and Arbitrary Code Execution | MITRE | www.trendmicro.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.