PT-2007-6945 · Componentone · Componentone Flexgrid

Elazar Broad

·

Published

2007-11-20

·

Updated

2017-07-29

·

CVE-2007-6028

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ComponentOne FlexGrid version 7.1 Light
Description The issue is related to multiple stack-based buffer overflows in the VSFlexGrid.VSFlexGridL ActiveX control. This can be exploited by remote attackers who send a long string in the Text, EditSelText, EditText, and CellFontName property values, potentially leading to a denial of service and possibly the execution of arbitrary code.
Recommendations For ComponentOne FlexGrid version 7.1 Light, consider disabling the VSFlexGrid.VSFlexGridL ActiveX control until a patch is available to prevent potential exploitation. Avoid using long strings in the Text, EditSelText, EditText, and CellFontName property values to minimize the risk of triggering the buffer overflows.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6028

Affected Products

Componentone Flexgrid