AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-2054

HIGH · CVSS 7.5 EPSS 3.38%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-04-30 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable.

CVE
CVE-2007-2054
Severity
HIGH
CVSS
7.5
EPSS
3.38%

Original NVD Description

Multiple format string vulnerabilities in AFFLIB before 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls in (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/aimage.cpp, (f) aimage/imager.cpp, and (g) tools/afxml.cpp. NOTE: the aimage.cpp vector (e) has since been recalled from the researcher's original advisory, since the code is not called in any version of AFFLIB.