{"api_version":"1","generated_at":"2026-07-23T06:04:04+00:00","cve":"CVE-2007-5730","urls":{"html":"https://cve.report/CVE-2007-5730","api":"https://cve.report/api/cve/CVE-2007-5730.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5730","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5730"},"summary":{"title":"CVE-2007-5730","description":"Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the \"net socket listen\" option, aka QEMU \"net socket\" heap overflow.  NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of \"NE2000 network driver and the socket code,\" but this is the correct identifier for the individual net socket listen vulnerability.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-10-30 22:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-787","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://taviso.decsystem.org/virtsec.pdf","name":"http://taviso.decsystem.org/virtsec.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Technical Description","Third Party Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"403"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10000","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10000","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/42985","name":"http://osvdb.org/42985","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.attrition.org/pipermail/vim/2007-October/001842.html","name":"http://www.attrition.org/pipermail/vim/2007-October/001842.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[VIM] Clarification on old QEMU/NE2000/Xen issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/1597","name":"http://www.vupen.com/english/advisories/2007/1597","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/29129","name":"http://secunia.com/advisories/29129","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"KVM Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38239","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38239","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/25095","name":"http://secunia.com/advisories/25095","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian update for qemu - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2007/dsa-1284","name":"http://www.debian.org/security/2007/dsa-1284","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1284-1 qemu","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://secunia.com/advisories/27486","name":"http://secunia.com/advisories/27486","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Mandriva update for xen - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/29963","name":"http://secunia.com/advisories/29963","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat update for xen - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:203","name":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:203","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support / Security / Advisories /  / MDKSA-2007:203 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:162","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:162","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support / Security / Advisories /  / MDVSA-2008:162 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0194.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0194.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/23731","name":"http://www.securityfocus.com/bid/23731","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"QEMU Multiple Local Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/25073","name":"http://secunia.com/advisories/25073","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","Vendor Advisory"],"title":"QEMU Various Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5730","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5730","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5730","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"5730","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"5730","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"qemu","cpe5":"qemu","cpe6":"0.8.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"5730","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"xen","cpe5":"xen","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2007-5730","organization":"Red Hat","lastmodified":"2007-11-02","contributor":"Mark J Cox","statementText":"Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-5729 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.","cve_year":"2007","cve_id":"5730","crc32":"d94566a2"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:39:13.614Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"23731","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/23731"},{"name":"MDKSA-2007:203","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:203"},{"name":"RHSA-2008:0194","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0194.html"},{"name":"qemu-net-socket-bo(38239)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38239"},{"name":"42985","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/42985"},{"name":"DSA-1284","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2007/dsa-1284"},{"name":"25073","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25073"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://taviso.decsystem.org/virtsec.pdf"},{"name":"27486","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27486"},{"name":"MDVSA-2008:162","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:162"},{"name":"oval:org.mitre.oval:def:10000","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10000"},{"name":"29963","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29963"},{"name":"ADV-2007-1597","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1597"},{"name":"29129","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29129"},{"name":"25095","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25095"},{"name":"20071030 Clarification on old QEMU/NE2000/Xen issues","tags":["mailing-list","x_refsource_VIM","x_transferred"],"url":"http://www.attrition.org/pipermail/vim/2007-October/001842.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-05-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the \"net socket listen\" option, aka QEMU \"net socket\" heap overflow.  NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of \"NE2000 network driver and the socket code,\" but this is the correct identifier for the individual net socket listen vulnerability."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"23731","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/23731"},{"name":"MDKSA-2007:203","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:203"},{"name":"RHSA-2008:0194","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0194.html"},{"name":"qemu-net-socket-bo(38239)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38239"},{"name":"42985","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/42985"},{"name":"DSA-1284","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2007/dsa-1284"},{"name":"25073","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25073"},{"tags":["x_refsource_MISC"],"url":"http://taviso.decsystem.org/virtsec.pdf"},{"name":"27486","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27486"},{"name":"MDVSA-2008:162","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:162"},{"name":"oval:org.mitre.oval:def:10000","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10000"},{"name":"29963","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29963"},{"name":"ADV-2007-1597","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1597"},{"name":"29129","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29129"},{"name":"25095","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25095"},{"name":"20071030 Clarification on old QEMU/NE2000/Xen issues","tags":["mailing-list","x_refsource_VIM"],"url":"http://www.attrition.org/pipermail/vim/2007-October/001842.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5730","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the \"net socket listen\" option, aka QEMU \"net socket\" heap overflow.  NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of \"NE2000 network driver and the socket code,\" but this is the correct identifier for the individual net socket listen vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"23731","refsource":"BID","url":"http://www.securityfocus.com/bid/23731"},{"name":"MDKSA-2007:203","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:203"},{"name":"RHSA-2008:0194","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2008-0194.html"},{"name":"qemu-net-socket-bo(38239)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38239"},{"name":"42985","refsource":"OSVDB","url":"http://osvdb.org/42985"},{"name":"DSA-1284","refsource":"DEBIAN","url":"http://www.debian.org/security/2007/dsa-1284"},{"name":"25073","refsource":"SECUNIA","url":"http://secunia.com/advisories/25073"},{"name":"http://taviso.decsystem.org/virtsec.pdf","refsource":"MISC","url":"http://taviso.decsystem.org/virtsec.pdf"},{"name":"27486","refsource":"SECUNIA","url":"http://secunia.com/advisories/27486"},{"name":"MDVSA-2008:162","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:162"},{"name":"oval:org.mitre.oval:def:10000","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10000"},{"name":"29963","refsource":"SECUNIA","url":"http://secunia.com/advisories/29963"},{"name":"ADV-2007-1597","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1597"},{"name":"29129","refsource":"SECUNIA","url":"http://secunia.com/advisories/29129"},{"name":"25095","refsource":"SECUNIA","url":"http://secunia.com/advisories/25095"},{"name":"20071030 Clarification on old QEMU/NE2000/Xen issues","refsource":"VIM","url":"http://www.attrition.org/pipermail/vim/2007-October/001842.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5730","datePublished":"2007-10-30T22:00:00.000Z","dateReserved":"2007-10-30T00:00:00.000Z","dateUpdated":"2024-08-07T15:39:13.614Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-30 22:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-787","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:qemu:qemu:0.8.2:*:*:*:*:*:*:*","matchCriteriaId":"27650033-1C9F-4175-A26F-D9082A36F079"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:*","matchCriteriaId":"C2B9CCC2-BAC5-4A65-B8D4-4B71EBBA0C2F"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*","matchCriteriaId":"A2E0C1F8-31F5-4F61-9DF7-E49B43D3C873"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*","matchCriteriaId":"0F92AB32-E7DE-43F4-B877-1F41FA162EC7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5730","Ordinal":"1","Title":"CVE-2007-5730","CVE":"CVE-2007-5730","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5730","Ordinal":"1","NoteData":"Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the \"net socket listen\" option, aka QEMU \"net socket\" heap overflow.  NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of \"NE2000 network driver and the socket code,\" but this is the correct identifier for the individual net socket listen vulnerability.","Type":"Description","Title":"CVE-2007-5730"},{"CveYear":"2007","CveId":"5730","Ordinal":"2","NoteData":"2007-10-30","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5730","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}