Show filters
158 Total Results
Displaying 41-50 of 158
Sort by:
Attacker Value
Unknown
CVE-2011-0329
Disclosure Date: February 21, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in the GetData method in the Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 allows remote attackers to read arbitrary files via directory traversal sequences in the fileID parameter.
0
Attacker Value
Unknown
CVE-2011-0330
Disclosure Date: February 21, 2011 (last updated October 04, 2023)
The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest property, which allows remote attackers to execute arbitrary WMI Query Language (WQL) statements via a crafted value, as demonstrated by a value that triggers disclosure of information about installed software.
0
Attacker Value
Unknown
CVE-2010-4742
Disclosure Date: February 18, 2011 (last updated October 04, 2023)
Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows remote attackers to execute arbitrary code via a long PlayFileName property value.
0
Attacker Value
Unknown
CVE-2011-0324
Disclosure Date: February 07, 2011 (last updated October 04, 2023)
Multiple heap-based buffer overflows in Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allow remote attackers to execute arbitrary code via a long (1) KeyString property, (2) NewPath parameter to the SetLocalIniFilePath method, or (3) NewPortPath parameter to the SetTabletPortPath method.
0
Attacker Value
Unknown
CVE-2011-0323
Disclosure Date: February 07, 2011 (last updated October 04, 2023)
Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary content.
0
Attacker Value
Unknown
CVE-2010-2793
Disclosure Date: December 08, 2010 (last updated October 04, 2023)
Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.
0
Attacker Value
Unknown
CVE-2010-2583
Disclosure Date: November 03, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
0
Attacker Value
Unknown
CVE-2010-2585
Disclosure Date: October 26, 2010 (last updated October 04, 2023)
Multiple buffer overflows in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls allow remote attackers to execute arbitrary code via a long (1) DestURL or (2) SourceFile property value.
0
Attacker Value
Unknown
CVE-2010-2584
Disclosure Date: October 26, 2010 (last updated October 04, 2023)
The Upload method in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls does not properly restrict certain property values, which allows remote attackers to read arbitrary files via a filename in the SourceFile property in conjunction with an http URL in the DestURL property.
0
Attacker Value
Unknown
CVE-2009-3737
Disclosure Date: August 17, 2010 (last updated October 04, 2023)
The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj method, which allows remote attackers to execute arbitrary code via a crafted HTML document.
0