CVE-2007-0148: Medium severity OmniGroup OmniWeb vulnerability
Published Jan 9, 2007
·Updated
Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the Javascript alert function.
Affected Software
1 affected component
OmniGroup OmniWeb=5.5.1
Remediation
Patch Available
Patch Available
Event History
Jan 9, 2007
CVE Published
06:28 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0148?
CVE-2007-0148 is considered a moderate severity vulnerability due to its potential to cause application crashes and execute arbitrary code.
2
How do I fix CVE-2007-0148?
To fix CVE-2007-0148, users should upgrade to a more recent and patched version of OmniWeb that resolves this vulnerability.
3
What is affected by CVE-2007-0148?
CVE-2007-0148 specifically affects OmniGroup OmniWeb version 5.5.1.
4
What type of vulnerability is CVE-2007-0148?
CVE-2007-0148 is a format string vulnerability that can be exploited via Javascript.
5
Can CVE-2007-0148 lead to data compromise?
Yes, CVE-2007-0148 can potentially allow attackers to execute arbitrary code, which may lead to data compromise.