vendor:
Office Viewer
by:
shinnai
N/A
CVSS
N/A
Denial of Service
CWE
Product Name: Office Viewer
Affected Version From: 3.2.0.5
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
Office Viewer (OA.ocx v. 3.2.0.5) multiple methods Denial of Service
The Office Viewer software, specifically the OA.ocx version 3.2.0.5, is vulnerable to multiple methods of denial of service attacks. The vulnerability allows an attacker to crash the software by exploiting certain methods such as DoOleCommand, FTPDownloadFile, FTPUploadFile, HttpUploadFile, Save, and SaveWebFile.
Mitigation:
Update to the latest version of the software.