{"api_version":"1","generated_at":"2026-07-23T10:15:53+00:00","cve":"CVE-2007-3880","urls":{"html":"https://cve.report/CVE-2007-3880","api":"https://cve.report/api/cve/CVE-2007-3880.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3880","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3880"},"summary":{"title":"CVE-2007-3880","description":"Format string vulnerability in srsexec in Sun Remote Services (SRS) Net Connect 3.2.3 and 3.2.4, as distributed in the SRS Proxy Core (SUNWsrspx) package, allows local users to gain privileges via format string specifiers in unspecified input that is logged through syslog.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-11-14 01:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-134","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securitytracker.com/id?1018893","name":"http://www.securitytracker.com/id?1018893","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Sun Remote Services Net Connect Format String Bug Lets Local Users Gain Root Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3711","name":"http://www.vupen.com/english/advisories/2007/3711","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/40836","name":"http://osvdb.org/40836","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/27512","name":"http://secunia.com/advisories/27512","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Sun SRS Net Connect Software \"srsexec\" Format String Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=610","name":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=610","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-103119-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-103119-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"#200581: Security Vulnerability in the Sun Remote Services (SRS) Net Connect Software","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/26313","name":"http://www.securityfocus.com/bid/26313","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Sun Remote Services Net Connect Software Local Format String Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-200581-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-200581-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3880","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3880","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3880","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"net_connect_software","cpe6":"3.2.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3880","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"net_connect_software","cpe6":"3.2.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3880","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sun","cpe5":"sunos","cpe6":"5.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3880","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sun","cpe5":"sunos","cpe6":"5.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3880","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sun","cpe5":"sunos","cpe6":"5.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:37:04.557Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"103119","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-103119-1"},{"name":"40836","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/40836"},{"name":"1018893","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018893"},{"name":"26313","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26313"},{"name":"ADV-2007-3711","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3711"},{"name":"27512","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27512"},{"name":"200581","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-200581-1"},{"name":"20071102 Sun Microsystems Solaris srsexec Format String Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=610"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-11-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"Format string vulnerability in srsexec in Sun Remote Services (SRS) Net Connect 3.2.3 and 3.2.4, as distributed in the SRS Proxy Core (SUNWsrspx) package, allows local users to gain privileges via format string specifiers in unspecified input that is logged through syslog."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-11-17T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"103119","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-103119-1"},{"name":"40836","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/40836"},{"name":"1018893","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018893"},{"name":"26313","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26313"},{"name":"ADV-2007-3711","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3711"},{"name":"27512","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27512"},{"name":"200581","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-200581-1"},{"name":"20071102 Sun Microsystems Solaris srsexec Format String Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=610"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-3880","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Format string vulnerability in srsexec in Sun Remote Services (SRS) Net Connect 3.2.3 and 3.2.4, as distributed in the SRS Proxy Core (SUNWsrspx) package, allows local users to gain privileges via format string specifiers in unspecified input that is logged through syslog."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"103119","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-103119-1"},{"name":"40836","refsource":"OSVDB","url":"http://osvdb.org/40836"},{"name":"1018893","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018893"},{"name":"26313","refsource":"BID","url":"http://www.securityfocus.com/bid/26313"},{"name":"ADV-2007-3711","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3711"},{"name":"27512","refsource":"SECUNIA","url":"http://secunia.com/advisories/27512"},{"name":"200581","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-200581-1"},{"name":"20071102 Sun Microsystems Solaris srsexec Format String Vulnerability","refsource":"IDEFENSE","url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=610"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-3880","datePublished":"2007-11-14T01:00:00.000Z","dateReserved":"2007-07-18T00:00:00.000Z","dateUpdated":"2024-08-07T14:37:04.557Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-11-14 01:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-134","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*","matchCriteriaId":"A2475113-CFE4-41C8-A86F-F2DA6548D224"},{"vulnerable":false,"criteria":"cpe:2.3:o:sun:sunos:5.9:*:*:*:*:*:*:*","matchCriteriaId":"A1E585DC-FC74-4BB0-96B7-C00B6DB610DF"},{"vulnerable":false,"criteria":"cpe:2.3:o:sun:sunos:5.10:*:*:*:*:*:*:*","matchCriteriaId":"E75493D0-F060-4CBA-8AB0-C4FE8B2A8C9B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sun:net_connect_software:3.2.3:*:*:*:*:*:*:*","matchCriteriaId":"C4CDB012-3681-4008-B69A-E87DC2A8AA0B"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:net_connect_software:3.2.4:*:*:*:*:*:*:*","matchCriteriaId":"A8781D62-937B-41CB-8C0C-BBF9B83D21A3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3880","Ordinal":"1","Title":"CVE-2007-3880","CVE":"CVE-2007-3880","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3880","Ordinal":"1","NoteData":"Format string vulnerability in srsexec in Sun Remote Services (SRS) Net Connect 3.2.3 and 3.2.4, as distributed in the SRS Proxy Core (SUNWsrspx) package, allows local users to gain privileges via format string specifiers in unspecified input that is logged through syslog.","Type":"Description","Title":"CVE-2007-3880"},{"CveYear":"2007","CveId":"3880","Ordinal":"2","NoteData":"2007-11-13","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3880","Ordinal":"3","NoteData":"2007-11-17","Type":"Other","Title":"Modified"}]}}}