AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-3873

MEDIUM · CVSS 6.9 EPSS 0.42%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-08-22 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.9. It may lead to a denial-of-service condition.

CVE
CVE-2007-3873
Severity
MEDIUM
CVSS
6.9
EPSS
0.42%

Original NVD Description

Stack-based buffer overflow in vstlib32.dll 1.2.0.1012 in the SSAPI Engine 5.0.0.1066 through 5.2.0.1012 in Trend Micro AntiSpyware 3.5 and PC-Cillin Internet Security 2007 15.0 through 15.3, when the Venus Spy Trap (VST) feature is enabled, allows local users to cause a denial of service (service crash) or execute arbitrary code via a file with a long pathname, which triggers the overflow during a ReadDirectoryChangesW callback notification.