vendor:
Phoenix Service Software
by:
Unknown
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Phoenix Service Software
Affected Version From: 2008.04.007.32837
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
Unknown
Nokia Phoenix Service Software ActiveX Controls Multiple Buffer Overflow Vulnerabilities
The Nokia Phoenix Service Software ActiveX controls are prone to multiple buffer-overflow vulnerabilities because they fail to properly bounds-check user-supplied data before copying it into insufficiently sized memory buffers. An attacker can exploit these issues to execute arbitrary code within the context of the application that invoked the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.
Mitigation:
Unknown