CVE-2006-6488
ICONICS Vessel / Gauge / Switch 8.02.140 - ActiveX Buffer Overflow
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX, allows remote attackers to execute arbitrary code via a long (1) FileName or (2) Filter argument.
Desbordamiento de búfer basado en pila en la función DoModal en el control de ActiveX Dialog Wrapper Module (DlgWrapper.dll) anterior a la 8.4.166.0, como el utilizado en el ICONICS OPC Enabled Gauge, Switch y Vessel ActiveX, permite a atacantes remotos la ejecución de código mediante un argumento largo en el (1) FileName or (2) Filter.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-12-12 CVE Reserved
- 2006-12-31 CVE Published
- 2008-09-25 First Exploit
- 2023-12-15 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://osvdb.org/32552 | Vdb Entry | |
http://www.kb.cert.org/vuls/id/251969 | Third Party Advisory | |
http://www.securityfocus.com/bid/21849 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/0025 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/31228 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/6570 | 2008-09-25 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/23583 | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Iconics Search vendor "Iconics" | Dialog Wrapper Module Activex Control Search vendor "Iconics" for product "Dialog Wrapper Module Activex Control" | <= 8.4.165.0 Search vendor "Iconics" for product "Dialog Wrapper Module Activex Control" and version " <= 8.4.165.0" | - |
Affected
|