Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-0340

Опубликовано: 04 мая 2011
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:advantech:advantech_studio:6.1:sp6_61.6.01.05:*:*:*:*:*:*
cpe:2.3:a:indusoft:thin_client:7.0:*:*:*:*:*:*:*
cpe:2.3:a:indusoft:web_studio:*:*:*:*:*:*:*:*
Версия до 7.0 (включая)
cpe:2.3:a:indusoft:web_studio:6.1:*:*:*:*:*:*:*
cpe:2.3:a:indusoft:web_studio:6.1:sp6:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.44861
Средний

9.3 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

github
больше 3 лет назад

Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.

EPSS

Процентиль: 97%
0.44861
Средний

9.3 Critical

CVSS2

Дефекты

CWE-119