{"api_version":"1","generated_at":"2026-07-23T05:00:39+00:00","cve":"CVE-2007-6253","urls":{"html":"https://cve.report/CVE-2007-6253","api":"https://cve.report/api/cve/CVE-2007-6253.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-6253","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-6253"},"summary":{"title":"CVE-2007-6253","description":"Multiple buffer overflows in Adobe Form Designer 5.0 and Form Client 5.0 allow remote attackers to execute arbitrary code via unknown vectors in the (1) Adobe File Dialog Button (FileDlg.dll) and the (2) Adobe Copy to Server Object (SvrCopy.dll) ActiveX controls.","state":"PUBLISHED","assigner":"certcc","published_at":"2008-03-12 00:44:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securitytracker.com/id?1019601","name":"http://www.securitytracker.com/id?1019601","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe Form Designer Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/362849","name":"http://www.kb.cert.org/vuls/id/362849","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"VU#362849 - Adobe Form Designer and Advanced Form Client ActiveX controls contain multiple buffer overflows","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0863/references","name":"http://www.vupen.com/english/advisories/2008/0863/references","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41142","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41142","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/29330","name":"http://secunia.com/advisories/29330","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Adobe Form Designer/Form Client Buffer Overflow Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/28210","name":"http://www.securityfocus.com/bid/28210","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Adobe Form Designer and Adobe Form Client Multiple Buffer-Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.adobe.com/support/security/bulletins/apsb08-09.html","name":"http://www.adobe.com/support/security/bulletins/apsb08-09.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Adobe - Security Advisories : APSB08-09: Update available to resolve critical vulnerabilities in Adobe Form Designer 5.0 and Adobe Form Client 5.0 Components","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-6253","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-6253","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"6253","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"form_client","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"6253","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"form_designer","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:02:35.586Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb08-09.html"},{"name":"28210","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/28210"},{"name":"29330","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29330"},{"name":"1019601","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1019601"},{"name":"VU#362849","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/362849"},{"name":"adobe-multiple-activex-bo(41142)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41142"},{"name":"ADV-2008-0863","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0863/references"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-03-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple buffer overflows in Adobe Form Designer 5.0 and Form Client 5.0 allow remote attackers to execute arbitrary code via unknown vectors in the (1) Adobe File Dialog Button (FileDlg.dll) and the (2) Adobe Copy to Server Object (SvrCopy.dll) ActiveX controls."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb08-09.html"},{"name":"28210","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/28210"},{"name":"29330","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29330"},{"name":"1019601","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1019601"},{"name":"VU#362849","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/362849"},{"name":"adobe-multiple-activex-bo(41142)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41142"},{"name":"ADV-2008-0863","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0863/references"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2007-6253","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple buffer overflows in Adobe Form Designer 5.0 and Form Client 5.0 allow remote attackers to execute arbitrary code via unknown vectors in the (1) Adobe File Dialog Button (FileDlg.dll) and the (2) Adobe Copy to Server Object (SvrCopy.dll) ActiveX controls."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.adobe.com/support/security/bulletins/apsb08-09.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb08-09.html"},{"name":"28210","refsource":"BID","url":"http://www.securityfocus.com/bid/28210"},{"name":"29330","refsource":"SECUNIA","url":"http://secunia.com/advisories/29330"},{"name":"1019601","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1019601"},{"name":"VU#362849","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/362849"},{"name":"adobe-multiple-activex-bo(41142)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41142"},{"name":"ADV-2008-0863","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0863/references"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2007-6253","datePublished":"2008-03-12T00:00:00.000Z","dateReserved":"2007-12-05T00:00:00.000Z","dateUpdated":"2024-08-07T16:02:35.586Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-03-12 00:44:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:form_client:5.0:*:*:*:*:*:*:*","matchCriteriaId":"2A6E54F6-AF15-4A2E-8C46-A6E043B158D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:form_designer:5.0:*:*:*:*:*:*:*","matchCriteriaId":"CBA789DC-3CDA-4613-8202-3501097D0B19"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"6253","Ordinal":"1","Title":"CVE-2007-6253","CVE":"CVE-2007-6253","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"6253","Ordinal":"1","NoteData":"Multiple buffer overflows in Adobe Form Designer 5.0 and Form Client 5.0 allow remote attackers to execute arbitrary code via unknown vectors in the (1) Adobe File Dialog Button (FileDlg.dll) and the (2) Adobe Copy to Server Object (SvrCopy.dll) ActiveX controls.","Type":"Description","Title":"CVE-2007-6253"},{"CveYear":"2007","CveId":"6253","Ordinal":"2","NoteData":"2008-03-11","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"6253","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}