CVE-2007-6387
Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping, ProSeries, QuickBooks, Quicken, QuickTax, and TurboTax, allow remote attackers to execute arbitrary code via long arguments to the (1) GetHistory, (2) GetSeedQuery, (3) SetSeedQuery, and possibly other methods. NOTE: some of these details are obtained from third party information.
Published:Dec 15, 2007
Last Modified:Apr 23, 2026
EPS:Dec 15, 2007
EPSS Score:0.57182
CVSS Score:9.3
Affected Products
Vendor
Product
Action
Vendor
Intuit
Product
Bookkeeping
Intuit
Bookkeeping
Vendor
Intuit
Product
Proseries
Intuit
Proseries
Vendor
Intuit
Product
Quickbooks
Intuit
Quickbooks
Vendor
Intuit
Product
Quicken
Intuit
Quicken
Vendor
Intuit
Product
Quicktax
Intuit
Quicktax
Vendor
Intuit
Product
Turbo Tax
Intuit
Turbo Tax
Vendor
Microsoft
Product
Activex
Microsoft
Activex
Vendor
Vantage Linquistics
Product
Answerworks
Vantage Linquistics
Answerworks
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
