trust is easily compromised
Showing 101 - 125 of 817 RSS Feed

ActiveX Files

Zero Day Initiative Advisory 11-172
Posted Jun 7, 2011
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 11-172 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell iPrint Client. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The flaw exists within the nipplib component which is used by both the ActiveX and Netscape compatible browser plugins. When handling the uri parameter from the user specified printer-url the process blindly copies user supplied data into a fixed-length buffer on the heap. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the browser.

tags | advisory, remote, arbitrary, activex
advisories | CVE-2011-1699
MD5 | 0c1f34fad469f2bfff8bea19c7eb5b6f
Magneto ICMP ActiveX 4.0.0.20 Code Execution
Posted May 27, 2011
Authored by boahat

Magneto ICMP ActiveX version 4.0.0.20 ICMPSendEchoRequest remote code execution exploit.

tags | exploit, remote, code execution, activex
MD5 | a657e43d78bac78e5fef921c4a4f6520
ICONICS WebHMI ActiveX Buffer Overflow
Posted May 12, 2011
Authored by sinn3r, sgb, bls | Site metasploit.com

This Metasploit module exploits a vulnerability found in ICONICS WebHMI's ActiveX control. By supplying a long string of data to the 'SetActiveXGUID' parameter, GenVersion.dll fails to do any proper bounds checking before this input is copied onto the stack, which causes a buffer overflow, and results arbitrary code execution under the context of the user.

tags | exploit, overflow, arbitrary, code execution, activex
advisories | OSVDB-72135
MD5 | f11343438dfb1690faea25b41bbf7127
Secunia Security Advisory 44417
Posted May 5, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been discovered in ICONICS VersionInfo ActiveX control, which can be exploited by malicious people to compromise a user's system.

tags | advisory, activex
MD5 | 73d6fb7f05cb66e70bced3cce03b12f4
ICONICS WebHMI Active-X Stack Overflow
Posted May 4, 2011
Authored by sgb, bls | Site security-assessment.com

ICONICS Genesis32 is a suite of OPC, SNMP, BACnet and Web-enabled HMI and SCADA applications. A stack overflow was found in an ActiveX control required by the WebHMI interface. This condition can be used to gain command execution. The affected control is 'GenVersion.dll' and has the ClassID of {CEFF5F48-BD2E-4D10-BAE5-AF729975E223}. This control is marked safe for scripting.

tags | exploit, web, overflow, activex
MD5 | 347ebf7b51aeb2cbff4dbe9ecd6446cd
Secunia Security Advisory 43474
Posted Apr 29, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Parvez Anwar has discovered a vulnerability in Data Dynamics ActiveBar ActiveX Control, which can be exploited by malicious people to compromise a user's system.

tags | advisory, activex
MD5 | 32f7d3465fd0484dbbae6b1a84eed06f
Secunia Security Advisory 43116
Posted Apr 28, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Secunia Research has discovered multiple vulnerabilities in InduSoft ISSymbol ActiveX control, which can be exploited by malicious people to compromise a user's system.

tags | advisory, vulnerability, activex
MD5 | d9971f80b201b9ed766cd6ff8e2c5321
Secunia Security Advisory 42928
Posted Apr 28, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Secunia Research has discovered multiple vulnerabilities in Advantech Studio ISSymbol ActiveX control, which can be exploited by malicious people to compromise a user's system.

tags | advisory, vulnerability, activex
MD5 | e920158c9bfaf737299aaae3bcbe3a52
RealPlayer 11 Browser Active-X Code Execution
Posted Apr 25, 2011
Authored by KedAns-Dz

RealPlayer 11 Browser suffers from an active-x related arbitrary code execution vulnerability.

tags | exploit, arbitrary, code execution, activex
MD5 | 6ec097a57fd28952769763a08e9cab42
Gesytec ElonFmt Active-X 1.1.14 Buffer Overflow
Posted Apr 21, 2011
Authored by LiquidWorm | Site zeroscience.mk

The Gesytec ElonFmt active-x control module suffers from a buffer overflow vulnerability. When a large buffer is sent to the pid item of the GetItem1 function in the elonfmt.ocx module, a few memory registers get overwritten including the SEH. Proof of concept exploit included. Version 1.1.14 is affected.

tags | exploit, overflow, activex, proof of concept
MD5 | 58e5b0bf42b9c4fd21638b378021c108
CA Output Management Web Viewer 11.0 / 11.5 Boundary Errors
Posted Apr 21, 2011
Authored by Ken Williams | Site www3.ca.com

CA Technologies support is alerting customers to security risks associated with CA Output Management Web Viewer. Two vulnerabilities exist that can allow a remote attacker to execute arbitrary code. CA Technologies has issued patches to address the vulnerabilities. The vulnerabilities are due to boundary errors in the UOMWV_HelperActiveX.ocx and PPSView.ocx ActiveX controls. A remote attacker can create a specially crafted web page to exploit the flaws and potentially execute arbitrary code.

tags | advisory, remote, web, arbitrary, vulnerability, activex
advisories | CVE-2011-1719
MD5 | bbeba246d3ce36be6a7d73c8e91b7577
Real Networks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution
Posted Apr 9, 2011
Authored by rgod, sinn3r | Site metasploit.com

This Metasploit module exploits a vulnerability in Real Networks Arcade Game's ActiveX control. The "exec" function found in InstallerDlg.dll (v2.6.0.445) allows remote attackers to run arbitrary commands on the victim machine.

tags | exploit, remote, arbitrary, activex
advisories | OSVDB-71559
MD5 | f1ee0f63d91f8cc6b0168cc0fbfa488c
RealNetworks RealGames Active-X Code Execution
Posted Apr 2, 2011
Authored by rgod | Site retrogod.altervista.org

RealNetworks RealGames StubbyUtil.ShellCtl.1 active-x control InstallerDlg.dll version 2.6.0.445 suffers from remote command and code execution vulnerabilities.

tags | exploit, remote, vulnerability, code execution, activex
systems | linux
MD5 | 8991b35d31c09f1f10bc4dde36e14059
Secunia Security Advisory 43360
Posted Mar 22, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Secunia Research has discovered a vulnerability in Honeywell ScanServer ActiveX Control, which can be exploited by malicious people to compromise a user's system.

tags | advisory, activex
MD5 | a5e56bb3cbbd2d00d69fbec83926f86a
Secunia Security Advisory 43466
Posted Mar 14, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Alexander Gavrun has discovered a vulnerability in Edraw Office Viewer Component ActiveX control, which can be exploited by malicious people to compromise a user's system.

tags | advisory, activex
MD5 | 703e9f881615c26a8037fe9ab6bc7ced
KingView 6.5.3 SCADA Active-X
Posted Mar 7, 2011
Authored by Carlos Mario Penagos Hollmann

KingView version 6.5.3 SCADA related active-x exploit.

tags | exploit, activex
MD5 | cf490f30ef094c615198e25a615d832e
F-Secure Internet Security 2011 ActiveX Denial Of Service
Posted Mar 4, 2011
Authored by Mehdi Boukazoula

F-Secure Internet Security 2011 ActiveX denial of service proof of concept exploit.

tags | exploit, denial of service, activex, proof of concept
MD5 | 730b69bbaeaa7cf7860c9946e0a3fa40
Secunia Security Advisory 43394
Posted Mar 3, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been discovered in PIPI Player PIPIWebPlayer ActiveX control, which can be exploited by malicious people to compromise a user's system.

tags | advisory, activex
MD5 | c87c3186cee121ac3f812646505aebf4
Edraw Office Viewer Component 7.4 Active-X Buffer Overflow
Posted Feb 25, 2011
Authored by Alexander Gavrun

Edraw Office Viewer component version 7.4 active-x related stack buffer overflow exploit.

tags | exploit, overflow, activex
MD5 | cbda59e598c9219aa5a7fbcb04fa2bdf
CA HIPS Arbitrary Code Execution
Posted Feb 25, 2011
Authored by Ken Williams | Site www3.ca.com

CA Technologies support is alerting customers to a security risk associated with CA Host-Based Intrusion Prevention System (HIPS). A vulnerability exists that can allow a remote attacker to execute arbitrary code. CA Technologies has issued patches to address the vulnerability. The vulnerability is due to insecure method implementation in the XMLSecDB ActiveX control that is utilized in CA HIPS components and products. A remote attacker can potentially execute arbitrary code if he can trick a user into visiting a malicious web page or opening a malicious file. Versions prior to 8.1.0.88 are affected.

tags | advisory, remote, web, arbitrary, activex
advisories | CVE-2011-1036
MD5 | 9551ac86c08c1110bdce359f65859c95
Zero Day Initiative Advisory 11-093
Posted Feb 24, 2011
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 11-093 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of CA Internet Security Suite 2010. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The flaw exists within the XMLSecDB ActiveX control which is installed with HIPSEngine component. SetXml and Save methods are implemented insecurely and can allow creation of an arbitrary file on the victim's system. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the user.

tags | advisory, remote, arbitrary, activex
advisories | CVE-2011-1036
MD5 | b8e041bac81fa25b0368170c3fca20f9
Zero Day Initiative Advisory 11-092
Posted Feb 24, 2011
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 11-092 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cisco Secure Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within CSDWebInstaller.ocx. The CSDWebInstallerCtrl ActiveX control allows downloading and executing any Cisco-signed executable files. By renaming a Cisco-signed executable file to inst.exe and putting it on a webserver, an attacker can subsequently exploit vulnerabilities in the Cisco-signed executable file remotely.

tags | advisory, remote, arbitrary, vulnerability, activex
systems | cisco
advisories | CVE-2011-0925
MD5 | 085e396d652f1e2079b1c44f5c0088b0
Zero Day Initiative Advisory 11-091
Posted Feb 24, 2011
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 11-091 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Cisco Secure Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within CSDWebInstaller.ocx ActiveX control. The vulnerable Cisco-signed ActiveX control verifies the signing authority names in the certificate chain but fails to properly verify the digital signature of an executable file that is downloaded and executed by the Cisco Secure Desktop installation process. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the browser.

tags | advisory, remote, arbitrary, activex
systems | cisco
advisories | CVE-2011-0926
MD5 | e21e1417d4a0fd870dc2a7dd5de9eefe
Secunia Security Advisory 42880
Posted Feb 18, 2011
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Secunia Research has discovered two vulnerabilities in Dell DellSystemLite.Scanner ActiveX control, which can be exploited by malicious people to disclose various information.

tags | advisory, vulnerability, activex
MD5 | 18e5f44ac049c850a45b1c78a36aaace
AoA MP4 Converter 4.1.0 ActiveX Stack Overflow
Posted Feb 8, 2011
Authored by Carlos Mario Penagos Hollmann

AoA MP4 Converter version 4.1.0 suffers from an active-x related stack overflow vulnerability.

tags | exploit, overflow, activex
MD5 | dbe6ffeb3c5f2c8cc9304a4f403c98de
Page 5 of 33
Back34567Next

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close