{"api_version":"1","generated_at":"2026-07-23T06:20:24+00:00","cve":"CVE-2007-3314","urls":{"html":"https://cve.report/CVE-2007-3314","api":"https://cve.report/api/cve/CVE-2007-3314.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3314","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3314"},"summary":{"title":"CVE-2007-3314","description":"Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-06-21 18:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34938","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34938","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://vuln.sg/salamander25-en.html","name":"http://vuln.sg/salamander25-en.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"[vuln.sg] Altap Salamander PE Viewer Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/25732","name":"http://secunia.com/advisories/25732","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Altap Salamander PDB Filename Handling Buffer Overflow - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24557","name":"http://www.securityfocus.com/bid/24557","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Altap Servant Salamander PE File Handling Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/37579","name":"http://osvdb.org/37579","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/2268","name":"http://www.vupen.com/english/advisories/2007/2268","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3314","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3314","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3314","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"altap","cpe5":"portable_executable_viewer","cpe6":"1.00","cpe7":"*","cpe8":"english_trial","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3314","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"altap","cpe5":"portable_executable_viewer","cpe6":"2.02","cpe7":"*","cpe8":"english_trial","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3314","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"altap","cpe5":"servant_salamander","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3314","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"altap","cpe5":"servant_salamander","cpe6":"2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:14:12.908Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"25732","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25732"},{"name":"37579","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37579"},{"name":"24557","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24557"},{"name":"ADV-2007-2268","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2268"},{"name":"salamander-peviewer-bo(34938)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34938"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://vuln.sg/salamander25-en.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-06-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"25732","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25732"},{"name":"37579","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37579"},{"name":"24557","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24557"},{"name":"ADV-2007-2268","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2268"},{"name":"salamander-peviewer-bo(34938)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34938"},{"tags":["x_refsource_MISC"],"url":"http://vuln.sg/salamander25-en.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-3314","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"25732","refsource":"SECUNIA","url":"http://secunia.com/advisories/25732"},{"name":"37579","refsource":"OSVDB","url":"http://osvdb.org/37579"},{"name":"24557","refsource":"BID","url":"http://www.securityfocus.com/bid/24557"},{"name":"ADV-2007-2268","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2268"},{"name":"salamander-peviewer-bo(34938)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34938"},{"name":"http://vuln.sg/salamander25-en.html","refsource":"MISC","url":"http://vuln.sg/salamander25-en.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-3314","datePublished":"2007-06-21T18:00:00.000Z","dateReserved":"2007-06-21T00:00:00.000Z","dateUpdated":"2024-08-07T14:14:12.908Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-06-21 18:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:altap:portable_executable_viewer:2.02:*:english_trial:*:*:*:*:*","matchCriteriaId":"2413620C-3733-4EA9-A3DC-610F51115B30"},{"vulnerable":true,"criteria":"cpe:2.3:a:altap:servant_salamander:2.5:*:*:*:*:*:*:*","matchCriteriaId":"724DDDA3-E43A-4FB6-9EC3-CA4FDB04D6A1"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:altap:portable_executable_viewer:1.00:*:english_trial:*:*:*:*:*","matchCriteriaId":"1D65118E-3262-48E4-8CBE-C282FD0EDEE0"},{"vulnerable":true,"criteria":"cpe:2.3:a:altap:servant_salamander:2.0:*:*:*:*:*:*:*","matchCriteriaId":"7EAB07E9-BF9A-45FA-AE20-75BD8B4B14FF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3314","Ordinal":"1","Title":"CVE-2007-3314","CVE":"CVE-2007-3314","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3314","Ordinal":"1","NoteData":"Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file.","Type":"Description","Title":"CVE-2007-3314"},{"CveYear":"2007","CveId":"3314","Ordinal":"2","NoteData":"2007-06-21","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3314","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}