vendor:
NewvCommon.ocx
by:
SecurityFocus
9.3
CVSS
HIGH
Insecure-Method Vulnerability, Stack-Based Buffer Overflow Vulnerability
20, 119
CWE
Product Name: NewvCommon.ocx
Affected Version From: 1.1.0.0
Affected Version To: 1.1.0.0
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010
Newv SmartClient ActiveX Control Multiple Vulnerabilities
The Newv SmartClient ActiveX control is prone to multiple insecure-method vulnerabilities and a stack-based buffer-overflow vulnerability. Successfully exploiting these issues allows remote attackers to create or overwrite arbitrary local files, to delete arbitrary files, and to execute arbitrary code. Failed exploit attempts will result in a denial-of-service condition.
Mitigation:
Update to the latest version of the Newv SmartClient ActiveX control.