CVE-2007-1403: Buffer Overflow
Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2) SRC, (3) AutoStart, (4) Sound, (5) DrawLogo, or (6) DrawProgress property value, different vectors than CVE-2006-6885.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1403?
CVE-2007-1403 has a high severity rating due to its potential for denial of service and arbitrary code execution.
How do I fix CVE-2007-1403?
To fix CVE-2007-1403, update to the latest version of Macromedia Shockwave that addresses this vulnerability.
What is affected by CVE-2007-1403?
CVE-2007-1403 affects Macromedia Shockwave version 10.1.4.20.
What types of attacks are possible with CVE-2007-1403?
CVE-2007-1403 allows for remote attacks that can result in a crash of Internet Explorer and potentially arbitrary code execution.
Can CVE-2007-1403 be exploited remotely?
Yes, CVE-2007-1403 can be exploited remotely by attackers through crafted input to the vulnerable Shockwave ActiveX control.