Vulnerability Details CVE-2007-6009
Multiple buffer overflows in ACD products allow user-assisted remote attackers to execute arbitrary code via a long section string in a (1) XBM or (2) XPM file to (a) ID_X.apl or (b) IDE_ACDStd.apl. NOTE: the PSP and LHA vectors are already covered by CVE-2007-4344 and CVE-2007-6007. NOTE: these might be integer overflows rather than buffer overflows.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.056
EPSS Ranking 89.7%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2007-6009
-
cpe:2.3:a:acdsee:photo_editor:4.0
-
cpe:2.3:a:acdsee:photo_manager:9.0
-
cpe:2.3:a:acdsee:pro_photo_manager:8.1