// For flags

CVE-2011-5167

Oracle Hyperion Strategic Finance 12.x - Tidestone Formula One WorkBook OLE Control TTF16.ocx Remote Heap Overflow

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter.

Desbordamiento de búfer basado en memoria dinámica en el método SetDevNames del control ActiveX Tidestone Formula One (TTF16.ocx) v6.3.5 Build 1 en Oracle Hyperion Strategic Finance v12.x y posiblemente anteriores, permite a atacantes remotos ejecutar código arbitrario a través de una cadena larga en el parámetro DriverName.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-11-07 First Exploit
  • 2012-09-15 CVE Reserved
  • 2012-09-15 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-10-04 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Oracle
Search vendor "Oracle"
Hyperion Strategic Finance
Search vendor "Oracle" for product "Hyperion Strategic Finance"
<= 12.0
Search vendor "Oracle" for product "Hyperion Strategic Finance" and version " <= 12.0"
-
Affected
Oracle
Search vendor "Oracle"
Hyperion Strategic Finance
Search vendor "Oracle" for product "Hyperion Strategic Finance"
11.1.2.1.0
Search vendor "Oracle" for product "Hyperion Strategic Finance" and version "11.1.2.1.0"
-
Affected
Tidestone
Search vendor "Tidestone"
Formula One Activex Control
Search vendor "Tidestone" for product "Formula One Activex Control"
6.3.5.1
Search vendor "Tidestone" for product "Formula One Activex Control" and version "6.3.5.1"
-
Affected