ge ge-communicator CVE-2017-7908 is a vulnerability in Ge Communicator
Published on October 2, 2018

A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML file that loads the ActiveX controls can trigger the vulnerability via unchecked function calls.

NVD

Weakness Type

Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().


Products Associated with CVE-2017-7908

Want to know whenever a new CVE is published for Ge Communicator? stack.watch will email you.

 

Affected Versions

GE Communicator Version Communicator 3.15 and prior. is affected by CVE-2017-7908

Exploit Probability

EPSS
0.25%
Percentile
48.54%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.