{"api_version":"1","generated_at":"2026-07-23T06:43:43+00:00","cve":"CVE-2007-2419","urls":{"html":"https://cve.report/CVE-2007-2419","api":"https://cve.report/api/cve/CVE-2007-2419.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2419","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2419"},"summary":{"title":"CVE-2007-2419","description":"Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability than CVE-2007-0328.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-06-06 10:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://osvdb.org/36983","name":"http://osvdb.org/36983","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/25509","name":"http://secunia.com/advisories/25509","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Macrovision FLEXnet boisweb.dll ActiveX Control Buffer Overflows - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2070","name":"http://www.vupen.com/english/advisories/2007/2070","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018195","name":"http://www.securitytracker.com/id?1018195","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Macrovision FLEXnet Connect Buffer Overflow in ActiveX Control Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/470585/100/0/threaded","name":"http://www.securityfocus.com/archive/1/470585/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.installshield.com/kb/view.asp?articleid=Q113020","name":"http://support.installshield.com/kb/view.asp?articleid=Q113020","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"View Document","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://dvlabs.tippingpoint.com/advisory/TPTI-07-09","name":"http://dvlabs.tippingpoint.com/advisory/TPTI-07-09","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"TippingPoint | DVLabs |","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34721","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34721","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2419","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2419","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2419","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macrovision","cpe5":"flexnet_connect","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2419","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macrovision","cpe5":"update_service","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2419","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macrovision","cpe5":"update_service","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2419","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macrovision","cpe5":"update_service","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:33:28.724Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.installshield.com/kb/view.asp?articleid=Q113020"},{"name":"macrovision-boisweb-bo(34721)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34721"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://dvlabs.tippingpoint.com/advisory/TPTI-07-09"},{"name":"ADV-2007-2070","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2070"},{"name":"36983","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36983"},{"name":"25509","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25509"},{"name":"20070605 TPTI-07-09: Macrovision FLEXnet boisweb.dll ActiveX Control Buffer Overflow Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/470585/100/0/threaded"},{"name":"1018195","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018195"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-06-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability than CVE-2007-0328."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://support.installshield.com/kb/view.asp?articleid=Q113020"},{"name":"macrovision-boisweb-bo(34721)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34721"},{"tags":["x_refsource_MISC"],"url":"http://dvlabs.tippingpoint.com/advisory/TPTI-07-09"},{"name":"ADV-2007-2070","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2070"},{"name":"36983","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36983"},{"name":"25509","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25509"},{"name":"20070605 TPTI-07-09: Macrovision FLEXnet boisweb.dll ActiveX Control Buffer Overflow Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/470585/100/0/threaded"},{"name":"1018195","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018195"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-2419","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability than CVE-2007-0328."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://support.installshield.com/kb/view.asp?articleid=Q113020","refsource":"CONFIRM","url":"http://support.installshield.com/kb/view.asp?articleid=Q113020"},{"name":"macrovision-boisweb-bo(34721)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34721"},{"name":"http://dvlabs.tippingpoint.com/advisory/TPTI-07-09","refsource":"MISC","url":"http://dvlabs.tippingpoint.com/advisory/TPTI-07-09"},{"name":"ADV-2007-2070","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2070"},{"name":"36983","refsource":"OSVDB","url":"http://osvdb.org/36983"},{"name":"25509","refsource":"SECUNIA","url":"http://secunia.com/advisories/25509"},{"name":"20070605 TPTI-07-09: Macrovision FLEXnet boisweb.dll ActiveX Control Buffer Overflow Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/470585/100/0/threaded"},{"name":"1018195","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018195"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-2419","datePublished":"2007-06-06T10:00:00.000Z","dateReserved":"2007-05-01T00:00:00.000Z","dateUpdated":"2024-08-07T13:33:28.724Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-06-06 10:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:macrovision:flexnet_connect:6.0:*:*:*:*:*:*:*","matchCriteriaId":"2B07D756-3DB4-4ECD-83FD-CB60830F9267"},{"vulnerable":true,"criteria":"cpe:2.3:a:macrovision:update_service:3.0:*:*:*:*:*:*:*","matchCriteriaId":"A09B825D-2B5C-4BA8-AF5D-AB0C3FB61BA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:macrovision:update_service:4.0:*:*:*:*:*:*:*","matchCriteriaId":"61E90832-465C-4C77-8171-36593FEF3DB0"},{"vulnerable":true,"criteria":"cpe:2.3:a:macrovision:update_service:5.0:*:*:*:*:*:*:*","matchCriteriaId":"8427D006-33CA-4677-9536-26596FB210D9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2419","Ordinal":"1","Title":"CVE-2007-2419","CVE":"CVE-2007-2419","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2419","Ordinal":"1","NoteData":"Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability than CVE-2007-0328.","Type":"Description","Title":"CVE-2007-2419"},{"CveYear":"2007","CveId":"2419","Ordinal":"2","NoteData":"2007-06-06","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2419","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}