Unrated severityNVD Advisory· Published Jun 11, 2007· Updated Apr 23, 2026
CVE-2007-3169
CVE-2007-3169
Description
Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long first argument to the HttpDownloadFile method.
Affected products
2cpe:2.3:a:edraw:office_viewer_component:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:edraw:office_viewer_component:*:*:*:*:*:*:*:*range: <=5.0
- cpe:2.3:a:edraw:office_viewer_component:4.0.5.20:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.securityfocus.com/bid/24229nvdExploit
- secunia.com/advisories/25418nvdVendor Advisory
- moaxb.blogspot.com/2007/05/moaxb-29-edraw-office-viewer-component.htmlnvd
- osvdb.org/36045nvd
- shinnai.altervista.org/viewtopic.phpnvd
- www.ocxt.com/archives/28nvd
- www.vupen.com/english/advisories/2007/1992nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/34590nvd
- www.exploit-db.com/exploits/4009nvd
News mentions
0No linked articles in our index yet.