1 results (0.003 seconds)

CVSS: 9.3EPSS: 1%CPEs: 2EXPL: 0

The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj method, which allows remote attackers to execute arbitrary code via a crafted HTML document. El control ActiveX Oracle Siebel Option Pack para IE no inicializa adecuadamente la memoria que usa el método NewBusObj, lo cual permite a atacantes remotos ejecutar código a su elección a través de documentos HTML manipulados. • http://secunia.com/advisories/40804 http://www.kb.cert.org/vuls/id/174089 http://www.osvdb.org/66926 http://www.vupen.com/english/advisories/2010/2028 • CWE-94: Improper Control of Generation of Code ('Code Injection') •