{"api_version":"1","generated_at":"2026-07-23T08:24:52+00:00","cve":"CVE-2007-0164","urls":{"html":"https://cve.report/CVE-2007-0164","api":"https://cve.report/api/cve/CVE-2007-0164.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0164","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0164"},"summary":{"title":"CVE-2007-0164","description":"Camouflage 1.2.1 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing certain bytes of the JPEG image with alternate password information.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-01-10 00:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/456541/100/0/threaded","name":"http://www.securityfocus.com/archive/1/456541/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/32651","name":"http://osvdb.org/32651","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html","name":"http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"503","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21939","name":"http://www.securityfocus.com/bid/21939","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Camouflage Security Password Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31375","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31375","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23578","name":"http://secunia.com/advisories/23578","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Camouflage Carrier File Password Bypass Security Issue - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0164","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0164","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"164","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"camouflage","cpe5":"camouflage","cpe6":"1.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:12:16.458Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"21939","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21939"},{"name":"23578","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23578"},{"name":"20070107 A Major design Bug in Camouflage 1.2.1 (latest)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/456541/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html"},{"name":"camouflage-password-security-bypass(31375)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31375"},{"name":"32651","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/32651"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Camouflage 1.2.1 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing certain bytes of the JPEG image with alternate password information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"21939","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21939"},{"name":"23578","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23578"},{"name":"20070107 A Major design Bug in Camouflage 1.2.1 (latest)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/456541/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html"},{"name":"camouflage-password-security-bypass(31375)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31375"},{"name":"32651","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/32651"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-0164","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Camouflage 1.2.1 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing certain bytes of the JPEG image with alternate password information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21939","refsource":"BID","url":"http://www.securityfocus.com/bid/21939"},{"name":"23578","refsource":"SECUNIA","url":"http://secunia.com/advisories/23578"},{"name":"20070107 A Major design Bug in Camouflage 1.2.1 (latest)","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/456541/100/0/threaded"},{"name":"http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html","refsource":"MISC","url":"http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html"},{"name":"camouflage-password-security-bypass(31375)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31375"},{"name":"32651","refsource":"OSVDB","url":"http://osvdb.org/32651"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-0164","datePublished":"2007-01-10T00:00:00.000Z","dateReserved":"2007-01-09T00:00:00.000Z","dateUpdated":"2024-08-07T12:12:16.458Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-01-10 00:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:camouflage:camouflage:1.2.1:*:*:*:*:*:*:*","matchCriteriaId":"23FFE3C1-0E9F-4862-8E1B-8D04741B85AD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"164","Ordinal":"1","Title":"CVE-2007-0164","CVE":"CVE-2007-0164","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"164","Ordinal":"1","NoteData":"Camouflage 1.2.1 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing certain bytes of the JPEG image with alternate password information.","Type":"Description","Title":"CVE-2007-0164"},{"CveYear":"2007","CveId":"164","Ordinal":"2","NoteData":"2007-01-09","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"164","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}