// For flags

CVE-2013-1516

Oracle Document Capture BlackIceDevMode.ocx ActiveX Remote Code Execution Vulnerability

Severity Score

4.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Unspecified vulnerability in the Oracle WebCenter Capture component in Oracle Fusion Middleware 10.1.3.5.1 allows remote authenticated users to affect availability via unknown vectors related to Import Server.

Vulnerabilidad no especificada en el componente Oracle WebCenter Capture en Oracle Fusion Middleware v10.1.3.5.1 permite a usuarios remotos autenticados afectar la disponibilidad mediante vectores desconocidos relacionados con Import Server.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Document Capture. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the BlackIceDevMode.ocx ActiveX control. This component performs insufficient bounds checking on user-supplied data passed in the SetAnnotationFont() method which results in stack corruption. This corruption can be leveraged to achieve code execution under the context of the process.

*Credits: Francis Provencher From Protek Research Lab's
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Partial
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-01-30 CVE Reserved
  • 2013-04-17 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Oracle
Search vendor "Oracle"
Fusion Middleware
Search vendor "Oracle" for product "Fusion Middleware"
10.1.3.5.1
Search vendor "Oracle" for product "Fusion Middleware" and version "10.1.3.5.1"
-
Affected