CVE-2007-6017 describes an unsafe Save method in the PVATLCalendar.PVCalendar.1 ActiveX control (pvcalendar.ocx) within Symantec Backup Exec for Windows Server (BEWS) versions 11d and 12.0. This vulnerability allows remote attackers to cause a denial of service (browser crash) or create/overwrite arbitrary files by manipulating specific string properties. The vulnerability has a CVSS score of 5.1, indicating a medium severity. It can be exploited remotely over the network (AV:N) with high attack complexity (AC:H) and requires no authentication (Au:N), leading to potential partial confidentiality, integrity, and availability impacts (C:P/I:P/A:P). Despite its age, there is no evidence of active exploitation, publicly available exploit code in Metasploit or ExploitDB, or significant community discussion or media coverage. Its EPSS score is low, suggesting a minimal likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11dCPE matchmatch criteria | cpe:2.3:a:symantec:backup_exec_for_windows_server:11d:11.0.6235:*:*:*:*:*:* | ||
11dCPE matchmatch criteria | cpe:2.3:a:symantec:backup_exec_for_windows_server:11d:11.0.7170:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:symantec:backup_exec_for_windows_server:12.0:12.0.1364:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.