{"api_version":"1","generated_at":"2026-07-23T10:18:41+00:00","cve":"CVE-2007-0326","urls":{"html":"https://cve.report/CVE-2007-0326","api":"https://cve.report/api/cve/CVE-2007-0326.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0326","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0326"},"summary":{"title":"CVE-2007-0326","description":"Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors.","state":"PUBLISHED","assigner":"certcc","published_at":"2007-09-18 20:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/854769","name":"http://www.kb.cert.org/vuls/id/854769","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","US Government Resource"],"title":"VU#854769 - PhotoChannel Networks Photo Upload Plugin ActiveX control stack buffer overflows","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/37958","name":"http://osvdb.org/37958","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/3181","name":"http://www.vupen.com/english/advisories/2007/3181","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018701","name":"http://www.securitytracker.com/id?1018701","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - PhotoChannel Networks Buffer Overflow in Photo Upload Plugin ActiveX Control Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26830","name":"http://secunia.com/advisories/26830","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PhotoChannel Networks Photo Upload Plugin ActiveX Control Buffer Overflows - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36643","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36643","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25685","name":"http://www.securityfocus.com/bid/25685","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PhotoChannel Networks Photo Upload Plugin ActiveX Control Multiple Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0326","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0326","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"326","vulnerable":"1","versionEndIncluding":"2.0.0.9","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photochannel","cpe5":"pni_digital_media_upload_plugin_activex_control","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:12:18.094Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2007-3181","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3181"},{"name":"VU#854769","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/854769"},{"name":"photochannel-photo-upload-bo(36643)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36643"},{"name":"25685","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25685"},{"name":"1018701","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018701"},{"name":"37958","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37958"},{"name":"26830","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26830"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-09-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"ADV-2007-3181","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3181"},{"name":"VU#854769","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/854769"},{"name":"photochannel-photo-upload-bo(36643)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36643"},{"name":"25685","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25685"},{"name":"1018701","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018701"},{"name":"37958","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37958"},{"name":"26830","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26830"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2007-0326","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2007-3181","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3181"},{"name":"VU#854769","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/854769"},{"name":"photochannel-photo-upload-bo(36643)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36643"},{"name":"25685","refsource":"BID","url":"http://www.securityfocus.com/bid/25685"},{"name":"1018701","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018701"},{"name":"37958","refsource":"OSVDB","url":"http://osvdb.org/37958"},{"name":"26830","refsource":"SECUNIA","url":"http://secunia.com/advisories/26830"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2007-0326","datePublished":"2007-09-18T20:00:00.000Z","dateReserved":"2007-01-17T00:00:00.000Z","dateUpdated":"2024-08-07T12:12:18.094Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-09-18 20:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:photochannel:pni_digital_media_upload_plugin_activex_control:*:*:*:*:*:*:*:*","versionEndIncluding":"2.0.0.9","matchCriteriaId":"13183B47-051E-4314-97AA-F1E7E54EA214"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"326","Ordinal":"1","Title":"CVE-2007-0326","CVE":"CVE-2007-0326","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"326","Ordinal":"1","NoteData":"Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors.","Type":"Description","Title":"CVE-2007-0326"},{"CveYear":"2007","CveId":"326","Ordinal":"2","NoteData":"2007-09-18","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"326","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}