6.8
CVSSv2

CVE-2007-4489

Published: 22/08/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote malicious users to execute arbitrary code via a long Username argument to the ReInit method.

Vulnerable Product Search on Vulmon Subscribe to Product

ecentrex voip client module

Exploits

<!-- 17/08/2007 044137 eCentrex VOIP Client module (uacomxocx 201) remote buffer overflow exploit (ie6 / xp sp2) passing more than 164 chars to ReInit method in Username argument EAX 41414131 ECX 0013D444 ASCII "AAAAAAAA EDX 00000000 EBX 00000000 ESP 0013D3A0 EBP 0013D458 ASCII "AAAAAAAA ESI 41414131 EDI 00000001 EIP 04C4C945 euacom ...