Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitrary code via (1) a long bstrUrl parameter to the StartModule method, (2) a long bstrParams parameter to the Check method, a long bstrUrl parameter to the (3) Download or (4) DownloadModule method during construction of a .ntr pathname, or a long bstrUrl parameter to the (5) Download or (6) DownloadModule method during construction of a URL.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: flexera
Published:
Updated: 2024-08-06T18:16:20.136Z
Reserved: 2011-12-30T00:00:00
Link: CVE-2012-0266
No data.
Status : Deferred
Published: 2012-01-15T03:55:13.060
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-0266
No data.
OpenCVE Enrichment
No data.
Weaknesses