CVE-2007-4963 is a visual truncation vulnerability in WinImage 8.10 and earlier, allowing remote attackers to spoof destination filenames within .IMG or .ISO files using long sequences of spaces. This flaw can be combined with directory traversal to trick users into overwriting arbitrary files. With a CVSS score of 9.3 (Critical), it presents a high risk of complete compromise of confidentiality, integrity, and availability, requiring medium attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:a:winimage:winimage:8.0:*:*:*:*:*:*:* | ||
8.10CPE matchmatch criteria | cpe:2.3:a:winimage:winimage:8.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.