{"api_version":"1","generated_at":"2026-07-23T08:09:24+00:00","cve":"CVE-2007-0348","urls":{"html":"https://cve.report/CVE-2007-0348","api":"https://cve.report/api/cve/CVE-2007-0348.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0348","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0348"},"summary":{"title":"CVE-2007-0348","description":"Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.","state":"PUBLISHED","assigner":"flexera","published_at":"2007-03-21 19:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/463405/100/0/threaded","name":"http://www.securityfocus.com/archive/1/463405/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/1043","name":"http://www.vupen.com/english/advisories/2007/1043","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"inode/x-empty","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/1042","name":"http://www.vupen.com/english/advisories/2007/1042","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33186","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33186","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/34314","name":"http://osvdb.org/34314","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/23032","name":"http://secunia.com/advisories/23032","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"InterActual Player IASystemInfo.dll ActiveX Control Buffer Overflow - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/34315","name":"http://osvdb.org/34315","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/23071","name":"http://www.securityfocus.com/bid/23071","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IASystemInfo.DLL ActiveX Control Remote Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/secunia_research/2007-37/advisory/","name":"http://secunia.com/secunia_research/2007-37/advisory/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"InterActual Player / CinePlayer IASystemInfo.dll ActiveX Control Buffer Overflow - Secunia Research - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/922969","name":"http://www.kb.cert.org/vuls/id/922969","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"VU#922969 - InterActual Player SyscheckObject ActiveX controls contain stack buffer overflows","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23075","name":"http://secunia.com/advisories/23075","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"CinePlayer IASystemInfo.dll ActiveX Control Buffer Overflow - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/24556","name":"http://secunia.com/advisories/24556","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"WinDVD IASystemInfo.dll ActiveX Control Buffer Overflow - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0348","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0348","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"348","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"interactual_technologies","cpe5":"interactual_player","cpe6":"2.60.12.0717","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"348","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"intervideo","cpe5":"windvd","cpe6":"7.0.27.172","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"348","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"roxio","cpe5":"cineplayer","cpe6":"3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:12:18.213Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"23075","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23075"},{"name":"interactual-iasysteminfo-bo(33186)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33186"},{"name":"34314","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/34314"},{"name":"23032","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23032"},{"name":"VU#922969","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/922969"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2007-37/advisory/"},{"name":"34315","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/34315"},{"name":"ADV-2007-1042","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1042"},{"name":"23071","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/23071"},{"name":"ADV-2007-1043","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1043"},{"name":"24556","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24556"},{"name":"20070321 Secunia Research: InterActual Player / CinePlayer IASystemInfo.dllActiveX Control Buffer Overflow","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/463405/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-03-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","shortName":"flexera"},"references":[{"name":"23075","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23075"},{"name":"interactual-iasysteminfo-bo(33186)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33186"},{"name":"34314","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/34314"},{"name":"23032","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23032"},{"name":"VU#922969","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/922969"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2007-37/advisory/"},{"name":"34315","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/34315"},{"name":"ADV-2007-1042","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1042"},{"name":"23071","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/23071"},{"name":"ADV-2007-1043","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1043"},{"name":"24556","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24556"},{"name":"20070321 Secunia Research: InterActual Player / CinePlayer IASystemInfo.dllActiveX Control Buffer Overflow","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/463405/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"PSIRT-CNA@flexerasoftware.com","ID":"CVE-2007-0348","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"23075","refsource":"SECUNIA","url":"http://secunia.com/advisories/23075"},{"name":"interactual-iasysteminfo-bo(33186)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33186"},{"name":"34314","refsource":"OSVDB","url":"http://osvdb.org/34314"},{"name":"23032","refsource":"SECUNIA","url":"http://secunia.com/advisories/23032"},{"name":"VU#922969","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/922969"},{"name":"http://secunia.com/secunia_research/2007-37/advisory/","refsource":"MISC","url":"http://secunia.com/secunia_research/2007-37/advisory/"},{"name":"34315","refsource":"OSVDB","url":"http://osvdb.org/34315"},{"name":"ADV-2007-1042","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1042"},{"name":"23071","refsource":"BID","url":"http://www.securityfocus.com/bid/23071"},{"name":"ADV-2007-1043","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1043"},{"name":"24556","refsource":"SECUNIA","url":"http://secunia.com/advisories/24556"},{"name":"20070321 Secunia Research: InterActual Player / CinePlayer IASystemInfo.dllActiveX Control Buffer Overflow","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/463405/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","assignerShortName":"flexera","cveId":"CVE-2007-0348","datePublished":"2007-03-21T19:00:00.000Z","dateReserved":"2007-01-18T00:00:00.000Z","dateUpdated":"2024-08-07T12:12:18.213Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-03-21 19:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:interactual_technologies:interactual_player:2.60.12.0717:*:*:*:*:*:*:*","matchCriteriaId":"B0D4F3E4-8FF4-40D3-A15C-DD6BDE6B28E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:intervideo:windvd:7.0.27.172:*:*:*:*:*:*:*","matchCriteriaId":"C4A56AA0-8C82-4A4B-9B99-903C326BE12F"},{"vulnerable":true,"criteria":"cpe:2.3:a:roxio:cineplayer:3.2:*:*:*:*:*:*:*","matchCriteriaId":"6CFD17E2-8A0E-456D-B4EE-AC4BB443013B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"348","Ordinal":"1","Title":"CVE-2007-0348","CVE":"CVE-2007-0348","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"348","Ordinal":"1","NoteData":"Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.","Type":"Description","Title":"CVE-2007-0348"},{"CveYear":"2007","CveId":"348","Ordinal":"2","NoteData":"2007-03-21","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"348","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}