Back to search
CVE-2007-6189
Published: Nov 30, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%%" sequence, which is misinterpreted as a Unicode string and decoded twice, leading to improper memory allocation and a heap-based buffer overflow.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
1018986
vdb-entry
x_refsource_SECTRACK
3405
third-party-advisory
x_refsource_SREASON
ADV-2007-3935
vdb-entry
x_refsource_VUPEN
27717
third-party-advisory
x_refsource_SECUNIA
4663
exploit
x_refsource_EXPLOIT-DB
20071120 EEYE: BitDefender Online Scanner 8 Double Decode Heap Overflow
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now