{"api_version":"1","generated_at":"2026-07-23T07:33:44+00:00","cve":"CVE-2007-2918","urls":{"html":"https://cve.report/CVE-2007-2918","api":"https://cve.report/api/cve/CVE-2007-2918.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2918","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2918"},"summary":{"title":"CVE-2007-2918","description":"Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow remote attackers to cause a denial of service (browser crash) and execute arbitrary code via unspecified vectors.","state":"PUBLISHED","assigner":"certcc","published_at":"2007-06-01 01:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/25514","name":"http://secunia.com/advisories/25514","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Logitech VideoCall Multiple ActiveX Controls Buffer Overflows - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2018","name":"http://www.vupen.com/english/advisories/2007/2018","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34658","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34658","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24254","name":"http://www.securityfocus.com/bid/24254","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Logitech VideoCall Multiple ActiveX Controls Multiple Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/330289","name":"http://www.kb.cert.org/vuls/id/330289","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"VU#330289 - Logitech VideoCall multiple ActiveX controls contain stack buffer overflows","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/36824","name":"http://osvdb.org/36824","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/36823","name":"http://osvdb.org/36823","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/36822","name":"http://osvdb.org/36822","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/36821","name":"http://osvdb.org/36821","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/36820","name":"http://osvdb.org/36820","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2918","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2918","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2918","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"logitech","cpe5":"videocall","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:57:54.517Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"VU#330289","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/330289"},{"name":"36821","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36821"},{"name":"25514","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25514"},{"name":"36820","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36820"},{"name":"36824","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36824"},{"name":"logitech-multiple-activex-bo(34658)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34658"},{"name":"24254","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24254"},{"name":"ADV-2007-2018","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2018"},{"name":"36822","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36822"},{"name":"36823","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36823"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-05-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow remote attackers to cause a denial of service (browser crash) and execute arbitrary code via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"VU#330289","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/330289"},{"name":"36821","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36821"},{"name":"25514","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25514"},{"name":"36820","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36820"},{"name":"36824","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36824"},{"name":"logitech-multiple-activex-bo(34658)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34658"},{"name":"24254","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24254"},{"name":"ADV-2007-2018","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2018"},{"name":"36822","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36822"},{"name":"36823","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36823"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2007-2918","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow remote attackers to cause a denial of service (browser crash) and execute arbitrary code via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"VU#330289","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/330289"},{"name":"36821","refsource":"OSVDB","url":"http://osvdb.org/36821"},{"name":"25514","refsource":"SECUNIA","url":"http://secunia.com/advisories/25514"},{"name":"36820","refsource":"OSVDB","url":"http://osvdb.org/36820"},{"name":"36824","refsource":"OSVDB","url":"http://osvdb.org/36824"},{"name":"logitech-multiple-activex-bo(34658)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34658"},{"name":"24254","refsource":"BID","url":"http://www.securityfocus.com/bid/24254"},{"name":"ADV-2007-2018","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2018"},{"name":"36822","refsource":"OSVDB","url":"http://osvdb.org/36822"},{"name":"36823","refsource":"OSVDB","url":"http://osvdb.org/36823"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2007-2918","datePublished":"2007-06-01T01:00:00.000Z","dateReserved":"2007-05-30T00:00:00.000Z","dateUpdated":"2024-08-07T13:57:54.517Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-06-01 01:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:logitech:videocall:*:*:*:*:*:*:*:*","matchCriteriaId":"BF42E13F-86E1-4E6D-B44D-09ACB25F92D5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2918","Ordinal":"1","Title":"CVE-2007-2918","CVE":"CVE-2007-2918","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2918","Ordinal":"1","NoteData":"Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow remote attackers to cause a denial of service (browser crash) and execute arbitrary code via unspecified vectors.","Type":"Description","Title":"CVE-2007-2918"},{"CveYear":"2007","CveId":"2918","Ordinal":"2","NoteData":"2007-05-31","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2918","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}