CVE-2007-1682
Summary
| CVE | CVE-2007-1682 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-08-27 20:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists, or (4) DeleteFile method. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Softartisans | Xfile | 1.0 | All | All | All |
| Application | Softartisans | Xfile | 1.0.6 | All | All | All |
| Application | Softartisans | Xfile | 1.0.7 | All | All | All |
| Application | Softartisans | Xfile | 1.0.8 | All | All | All |
| Application | Softartisans | Xfile | 1.01 | All | All | All |
| Application | Softartisans | Xfile | 1.1 | All | All | All |
| Application | Softartisans | Xfile | 1.1.1 | All | All | All |
| Application | Softartisans | Xfile | 1.1.2 | All | All | All |
| Application | Softartisans | Xfile | 1.1.3 | All | All | All |
| Application | Softartisans | Xfile | 1.1.4 | All | All | All |
| Application | Softartisans | Xfile | 1.1.5 | All | All | All |
| Application | Softartisans | Xfile | 1.1.6 | All | All | All |
| Application | Softartisans | Xfile | 1.1.7 | All | All | All |
| Application | Softartisans | Xfile | 2.0 | All | All | All |
| Application | Softartisans | Xfile | 2.0.2 | All | All | All |
| Application | Softartisans | Xfile | 2.0.3 | All | All | All |
| Application | Softartisans | Xfile | 2.1.3 | All | All | All |
| Application | Softartisans | Xfile | 2.1.4 | All | All | All |
| Application | Softartisans | Xfile | 2.1.5 | All | All | All |
| Application | Softartisans | Xfile | 2.1.6 | All | All | All |
| Application | Softartisans | Xfile | 2.1.7 | All | All | All |
| Application | Softartisans | Xfile | 2.2.3 | All | All | All |
| Application | Softartisans | Xfile | 2.2.4 | All | All | All |
| Application | Softartisans | Xfile | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VU#914785 - SoftArtisans XFile FileManager ActiveX control stack buffer overflows | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| XFile: ActiveX Client Side File Upload | af854a3a-2127-422b-91ae-364da2661108 | support.softartisans.com | |
| SoftArtisans XFile FileManager ActiveX Control Multiple Buffer Overflows - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SoftArtisans XFile FileManager ActiveX Control Multiple Buffer Overflow Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.