header-logo
Suggest Exploit
vendor:
Phoenix Service Software
by:
Unknown
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Phoenix Service Software
Affected Version From: 2008.04.007.32837
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Metasploit:
Other Scripts:
Platforms Tested:
Unknown

Nokia Phoenix Service Software ActiveX Controls Multiple Buffer Overflow Vulnerabilities

The Nokia Phoenix Service Software ActiveX controls are prone to multiple buffer-overflow vulnerabilities because they fail to properly bounds-check user-supplied data before copying it into insufficiently sized memory buffers. An attacker can exploit these issues to execute arbitrary code within the context of the application that invoked the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.

Mitigation:

Unknown
Source

Exploit-DB raw data: