{"api_version":"1","generated_at":"2026-07-23T04:56:43+00:00","cve":"CVE-2007-3536","urls":{"html":"https://cve.report/CVE-2007-3536","api":"https://cve.report/api/cve/CVE-2007-3536.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3536","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3536"},"summary":{"title":"CVE-2007-3536","description":"Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-07-03 20:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.6","severity":"","vector":"AV:N/AC:H/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:C/I:C/A:C","baseScore":7.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://www.exploit-db.com/exploits/4123","name":"https://www.exploit-db.com/exploits/4123","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"AMX Corp. VNC ActiveX Control - 'AmxVnc.dll 1.0.13.0' Remote Buffer Overflow - Windows remote Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24703","name":"http://www.securityfocus.com/bid/24703","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"AMX AMXVNC.DLL ActiveX Control Multiple Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/37672","name":"http://osvdb.org/37672","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/2387","name":"http://www.vupen.com/english/advisories/2007/2387","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/25891","name":"http://secunia.com/advisories/25891","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"AMX VNC ActiveX Control Buffer Overflow Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35155","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35155","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3536","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3536","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3536","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"amx","cpe5":"netlinx_vnc_activex_control","cpe6":"1.0.13.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:21:36.111Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"amxnetlinx-hostpasswordlogfile-bo(35155)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35155"},{"name":"24703","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24703"},{"name":"37672","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37672"},{"name":"4123","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/4123"},{"name":"25891","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25891"},{"name":"ADV-2007-2387","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2387"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-06-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"amxnetlinx-hostpasswordlogfile-bo(35155)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35155"},{"name":"24703","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24703"},{"name":"37672","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37672"},{"name":"4123","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/4123"},{"name":"25891","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25891"},{"name":"ADV-2007-2387","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2387"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-3536","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"amxnetlinx-hostpasswordlogfile-bo(35155)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35155"},{"name":"24703","refsource":"BID","url":"http://www.securityfocus.com/bid/24703"},{"name":"37672","refsource":"OSVDB","url":"http://osvdb.org/37672"},{"name":"4123","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/4123"},{"name":"25891","refsource":"SECUNIA","url":"http://secunia.com/advisories/25891"},{"name":"ADV-2007-2387","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2387"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-3536","datePublished":"2007-07-03T20:00:00.000Z","dateReserved":"2007-07-03T00:00:00.000Z","dateUpdated":"2024-08-07T14:21:36.111Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-07-03 20:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:C/I:C/A:C","baseScore":7.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":4.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:amx:netlinx_vnc_activex_control:1.0.13.0:*:*:*:*:*:*:*","matchCriteriaId":"869918D2-6CBE-445A-BFFC-E9DECA4C0FE1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3536","Ordinal":"1","Title":"CVE-2007-3536","CVE":"CVE-2007-3536","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3536","Ordinal":"1","NoteData":"Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values.","Type":"Description","Title":"CVE-2007-3536"},{"CveYear":"2007","CveId":"3536","Ordinal":"2","NoteData":"2007-07-03","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3536","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}