Unrated severityNVD Advisory· Published Aug 15, 2007· Updated Apr 23, 2026
CVE-2007-4278
CVE-2007-4278
Description
Stack-based buffer overflow in the giomgr process in ESRI ArcSDE service 9.2, as used with ArcGIS, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number that requires more than 8 bytes to represent in ASCII, which triggers the overflow in an sprintf function call.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- downloads.esri.com/support/downloads/other_/ArcSDE-92sp3-issues.htmnvdVendor Advisory
- securitytracker.com/idnvdBroken LinkThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/25334nvdBroken LinkThird Party AdvisoryVDB Entry
- www.vupen.com/english/advisories/2007/2911nvdBroken LinkThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/36042nvdThird Party AdvisoryVDB Entry
- labs.idefense.com/intelligence/vulnerabilities/display.phpnvdBroken Link
- secunia.com/advisories/26452nvdBroken Link
News mentions
0No linked articles in our index yet.