CVE-2007-5279 describes a critical heap-based buffer overflow vulnerability in ConeXware PowerArchiver versions prior to 10.20.21, which could allow remote attackers to execute arbitrary code by supplying a specially crafted BlackHole archive containing an excessively long filename. This vulnerability carries a CVSS score of 9.3, indicating high severity due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. Despite its age and high severity, there is no evidence of active exploitation, publicly available exploit code in Metasploit or ExploitDB, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.10CPE matchmatch criteria | cpe:2.3:a:conexware:powerarchiver:8.10:*:*:*:*:*:*:* | ||
8.60CPE matchmatch criteria | cpe:2.3:a:conexware:powerarchiver:8.60:*:*:*:*:*:*:* | ||
9.5_beta_4CPE matchmatch criteria | cpe:2.3:a:conexware:powerarchiver:9.5_beta_4:*:*:*:*:*:*:* | ||
9.5_beta_5CPE matchmatch criteria | cpe:2.3:a:conexware:powerarchiver:9.5_beta_5:*:*:*:*:*:*:* | ||
9.25CPE matchmatch criteria | cpe:2.3:a:conexware:powerarchiver:9.25:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.