vendor:
Edraw Diagram Component
by:
Senator of Pirates
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Edraw Diagram Component
Affected Version From: Edraw Diagram Component 5
Affected Version To: Other versions may also be affected.
Patch Exists: Yes
Related CWE: N/A
CPE: a:edrawsoft:edraw_diagram_component
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 EN
2012
Edraw Diagram Component ActiveX Control Remote Buffer Overflow Vulnerability
Edraw Diagram Component ActiveX control ('EDBoard.ocx') is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. An attacker can exploit this issue to execute arbitrary code in the context of the application, usually Internet Explorer, using the ActiveX control. Failed attacks will likely cause denial-of-service conditions.
Mitigation:
Apply the latest security patches and updates from the vendor.