CVE Database
/

CVE-2011-0340

Back to search

CVE-2011-0340

Published: May 4, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.

VendorProductVersions

n/a

n/a

affected
n/a

References

43116
third-party-advisory
x_refsource_SECUNIA
47596
vdb-entry
x_refsource_BID
ADV-2011-1116
vdb-entry
x_refsource_VUPEN
42928
third-party-advisory
x_refsource_SECUNIA
ADV-2011-1115
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now