{"api_version":"1","generated_at":"2026-07-23T08:31:23+00:00","cve":"CVE-2007-5257","urls":{"html":"https://cve.report/CVE-2007-5257","api":"https://cve.report/api/cve/CVE-2007-5257.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5257","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5257"},"summary":{"title":"CVE-2007-5257","description":"Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-10-06 17:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/27017","name":"http://secunia.com/advisories/27017","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"EDraw Office Viewer Component ActiveX Control Buffer Overflow - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3329","name":"http://www.vupen.com/english/advisories/2007/3329","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/37724","name":"http://osvdb.org/37724","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.exploit-db.com/exploits/4474","name":"https://www.exploit-db.com/exploits/4474","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EDraw Office Viewer Component 5.3 - 'FtpDownloadFile()' Remote Buffer Overflow - Windows dos Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://shinnai.altervista.org/exploits/txt/TXT_O5FvsIzILBHQr7QbK2kD.html","name":"http://shinnai.altervista.org/exploits/txt/TXT_O5FvsIzILBHQr7QbK2kD.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"shinnai.altervista.org","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36879","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36879","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25892","name":"http://www.securityfocus.com/bid/25892","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"EDraw Office Viewer Component FtpDownloadFile ActiveX Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5257","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5257","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5257","vulnerable":"1","versionEndIncluding":"5.3.220.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"edraw","cpe5":"office_viewer_component","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:24:42.284Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"37724","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37724"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://shinnai.altervista.org/exploits/txt/TXT_O5FvsIzILBHQr7QbK2kD.html"},{"name":"27017","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27017"},{"name":"edraw-viewer-ftpdownloadfile-bo(36879)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36879"},{"name":"25892","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25892"},{"name":"4474","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/4474"},{"name":"ADV-2007-3329","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3329"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"37724","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37724"},{"tags":["x_refsource_MISC"],"url":"http://shinnai.altervista.org/exploits/txt/TXT_O5FvsIzILBHQr7QbK2kD.html"},{"name":"27017","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27017"},{"name":"edraw-viewer-ftpdownloadfile-bo(36879)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36879"},{"name":"25892","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25892"},{"name":"4474","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/4474"},{"name":"ADV-2007-3329","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3329"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5257","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"37724","refsource":"OSVDB","url":"http://osvdb.org/37724"},{"name":"http://shinnai.altervista.org/exploits/txt/TXT_O5FvsIzILBHQr7QbK2kD.html","refsource":"MISC","url":"http://shinnai.altervista.org/exploits/txt/TXT_O5FvsIzILBHQr7QbK2kD.html"},{"name":"27017","refsource":"SECUNIA","url":"http://secunia.com/advisories/27017"},{"name":"edraw-viewer-ftpdownloadfile-bo(36879)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36879"},{"name":"25892","refsource":"BID","url":"http://www.securityfocus.com/bid/25892"},{"name":"4474","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/4474"},{"name":"ADV-2007-3329","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3329"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5257","datePublished":"2007-10-06T17:00:00.000Z","dateReserved":"2007-10-06T00:00:00.000Z","dateUpdated":"2024-08-07T15:24:42.284Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-06 17:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:edraw:office_viewer_component:*:*:*:*:*:*:*:*","versionEndIncluding":"5.3.220.1","matchCriteriaId":"2D997868-C28E-47D4-991A-D250301F1036"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5257","Ordinal":"1","Title":"CVE-2007-5257","CVE":"CVE-2007-5257","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5257","Ordinal":"1","NoteData":"Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Component 5.3.220.1 and earlier allows remote attackers to execute arbitrary code via long strings in the first and second arguments to the FtpDownloadFile method, a different vector than CVE-2007-4821 and CVE-2007-3169.","Type":"Description","Title":"CVE-2007-5257"},{"CveYear":"2007","CveId":"5257","Ordinal":"2","NoteData":"2007-10-06","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5257","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}