CVE-2007-3696
CA ERwin Data Model Validator (formerly AllFusion Data Model Validator) allows remote attackers to (1) cause a denial of service (application hang) via a malformed .EXP database file and (2) cause a denial of service (aaplication crash) via a crafted .EXP database file, which triggers a NULL dereference.
Date published : 2007-07-11
http://www.securityfocus.com/bid/24814
http://www.eleytt.com/advisories/eleytt_ALLFUSIONDATAMODEL.pdf