9.3
CVSSv2

CVE-2008-2684

Published: 12/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote malicious users to execute arbitrary code via long strings in the two arguments to the DownloadImageFileURL method, which trigger memory corruption. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

blackice black ice barcode sdk 5.01

Exploits

----------------------------------------------------------------------------- Black Ice Software Inc Barcode SDK (BIDIBocx) Arbitrary File Download and Memory Corruption url: wwwblackicecom File : BIDIBocx Ver : 10930 CLSID: {D2797899-BE27-4CDB-892F-4FDC26EA9BA9} Mark: RegKey Safe for Script: True RegKey Safe for In ...