CVE-2007-0062

Integer overflow in the ISC dhcpd 3.0.x before 3.0.7 and 3.1.x before 3.1.1; and the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528; allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a malformed DHCP packet with a large dhcp-max-message-size that triggers a stack-based buffer overflow, related to servers configured to send many DHCP options to clients.

Published: 2007-09-21 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2007-0062 is rated High Risk (71.7/100): CVSS Critical severity, with high exploitation likelihood (EPSS 5.51%, 90th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2007-0062

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-10 5.40% 5.51% +0.11%
2 2025-07-08 6.30% 5.40% -0.90%
3 2025-03-30 6.30%

Full EPSS history (12 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2007-0062

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2007-0062

OS Trackers for CVE-2007-0062

vendor priority summary link
gentoo normal CVE-2007-0062: 2 GLSA(s) (200711-23, 200808-05), 3 atom(s) (app-emulation/vmware-player, app-emulation/vmware-workstation, net-misc/dhcp); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2007-0062
redhat low https://access.redhat.com/security/cve/CVE-2007-0062
ubuntu medium CVE-2007-0062 medium priority: Ubuntu including 5 source packages (linux-restricted-modules-2.6.17, linux-restricted-modules-2.6.20, vmware-player, vmware-player-kernel-2.6.15, vmware-server), 13 status rows across 5 suites (dapper, edgy, feisty, gutsy, upstream): released 10, DNE 3. https://ubuntu.com/security/CVE-2007-0062

Vendor comments (NVD) for CVE-2007-0062

  • Red Hat (2008-06-03T00:00:00)

    The Red Hat Security Response Team has rated this issue as having low security impact. The risks associated with fixing this bug are greater than the low severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 2.1, 3, 4, or 5: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-0062

Affected software / configurations for CVE-2007-0062

Vendor Product Version Raw CPE
vmware ace 1.0.3 cpe:2.3:a:vmware:ace:1.0.3:*:*:*:*:*:*:*
vmware ace 2.0 cpe:2.3:a:vmware:ace:2.0:*:*:*:*:*:*:*
vmware player 1.0.4 cpe:2.3:a:vmware:player:1.0.4:*:*:*:*:*:*:*
vmware player 2.0 cpe:2.3:a:vmware:player:2.0:*:*:*:*:*:*:*
vmware server 1.0.3 cpe:2.3:a:vmware:server:1.0.3:*:*:*:*:*:*:*
vmware vmware_workstation 6.0.1 cpe:2.3:a:vmware:vmware_workstation:6.0.1:*:*:*:*:*:*:*
vmware workstation 3.4 cpe:2.3:a:vmware:workstation:3.4:*:*:*:*:*:*:*
vmware workstation 4.0 cpe:2.3:a:vmware:workstation:4.0:*:*:*:*:*:*:*
vmware workstation 4.0.1 cpe:2.3:a:vmware:workstation:4.0.1:*:*:*:*:*:*:*
vmware workstation 4.0.2 cpe:2.3:a:vmware:workstation:4.0.2:*:*:*:*:*:*:*
vmware workstation 4.5.2 cpe:2.3:a:vmware:workstation:4.5.2:*:*:*:*:*:*:*
vmware workstation 5.5.0_build_13124 cpe:2.3:a:vmware:workstation:5.5.0_build_13124:*:*:*:*:*:*:*
vmware workstation 5.5.1 cpe:2.3:a:vmware:workstation:5.5.1:*:*:*:*:*:*:*
vmware workstation 5.5.1_build_19175 cpe:2.3:a:vmware:workstation:5.5.1_build_19175:*:*:*:*:*:*:*
vmware workstation 5.5.3_build_34685 cpe:2.3:a:vmware:workstation:5.5.3_build_34685:*:*:*:*:*:*:*
vmware workstation 5.5.3_build_42958 cpe:2.3:a:vmware:workstation:5.5.3_build_42958:*:*:*:*:*:*:*
vmware workstation 5.5.4 cpe:2.3:a:vmware:workstation:5.5.4:*:*:*:*:*:*:*
vmware workstation 5.5.4_build_44386 cpe:2.3:a:vmware:workstation:5.5.4_build_44386:*:*:*:*:*:*:*
vmware workstation 6.0 cpe:2.3:a:vmware:workstation:6.0:*:*:*:*:*:*:*

References for CVE-2007-0062

URL Tags
http://bugs.gentoo.org/show_bug.cgi?id=227135
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html
http://secunia.com/advisories/26890 Vendor Advisory
http://secunia.com/advisories/27694 Vendor Advisory
http://secunia.com/advisories/27706 Vendor Advisory
http://secunia.com/advisories/31396 Vendor Advisory
http://secunia.com/advisories/34263 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200711-23.xml
http://security.gentoo.org/glsa/glsa-200808-05.xml
http://wiki.rpath.com/Advisories:rPSA-2009-0041
http://www.iss.net/threats/275.html Patch
http://www.mandriva.com/security/advisories?name=MDVSA-2009:153
http://www.securityfocus.com/archive/1/501759/100/0/threaded
http://www.securityfocus.com/bid/25729 Patch
http://www.securitytracker.com/id?1018717
http://www.ubuntu.com/usn/usn-543-1
http://www.vmware.com/support/ace/doc/releasenotes_ace.html Patch
http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html Patch
http://www.vmware.com/support/player/doc/releasenotes_player.html Patch
http://www.vmware.com/support/player2/doc/releasenotes_player2.html Patch
http://www.vmware.com/support/server/doc/releasenotes_server.html Patch
http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html Patch
http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html Patch
http://www.vupen.com/english/advisories/2007/3229 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=339561
https://exchange.xforce.ibmcloud.com/vulnerabilities/33102
cvelogic Threat Intelligence