1 results (0.010 seconds)

CVSS: 9.3EPSS: 91%CPEs: 3EXPL: 3

Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter. Desbordamiento de búfer basado en memoria dinámica en el método SetDevNames del control ActiveX Tidestone Formula One (TTF16.ocx) v6.3.5 Build 1 en Oracle Hyperion Strategic Finance v12.x y posiblemente anteriores, permite a atacantes remotos ejecutar código arbitrario a través de una cadena larga en el parámetro DriverName. • https://www.exploit-db.com/exploits/18092 http://retrogod.altervista.org/9sg_ttf16.html http://secunia.com/advisories/46764 http://www.exploit-db.com/exploits/18092 http://www.osvdb.org/76913 http://www.saintcorporation.com/cgi-bin/exploit_info/oracle_hyperion_financial_mgmt_activex_heap http://www.securityfocus.com/bid/50565 https://exchange.xforce.ibmcloud.com/vulnerabilities/71163 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •