CVE-2013-1516
Oracle Document Capture BlackIceDevMode.ocx ActiveX Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the Oracle WebCenter Capture component in Oracle Fusion Middleware 10.1.3.5.1 allows remote authenticated users to affect availability via unknown vectors related to Import Server.
Vulnerabilidad no especificada en el componente Oracle WebCenter Capture en Oracle Fusion Middleware v10.1.3.5.1 permite a usuarios remotos autenticados afectar la disponibilidad mediante vectores desconocidos relacionados con Import Server.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Document Capture. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the BlackIceDevMode.ocx ActiveX control. This component performs insufficient bounds checking on user-supplied data passed in the SetAnnotationFont() method which results in stack corruption. This corruption can be leveraged to achieve code execution under the context of the process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-01-30 CVE Reserved
- 2013-04-17 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 | 2013-10-11 | |
http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html | 2013-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Fusion Middleware Search vendor "Oracle" for product "Fusion Middleware" | 10.1.3.5.1 Search vendor "Oracle" for product "Fusion Middleware" and version "10.1.3.5.1" | - |
Affected
|