CVE-2017-7908

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
02/10/2018
Last modified:
09/10/2019

Description

A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML file that loads the ActiveX controls can trigger the vulnerability via unchecked function calls.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gigasoft:proessentials:*:*:*:*:*:*:*:* 5 (including)
cpe:2.3:a:ge:ge_communicator:*:*:*:*:*:*:*:* 3.15 (including)