Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: flexera
Published: 2011-05-04T22:00:00
Updated: 2024-08-06T21:51:07.976Z
Reserved: 2011-01-06T00:00:00
Link: CVE-2011-0340
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-05-04T22:55:01.467
Modified: 2024-11-21T01:23:46.210
Link: CVE-2011-0340
Redhat
No data.