PT-2009-2572 · Microsoft+1 · Activex+1

Shinnai

·

Published

2009-08-27

·

Updated

2017-09-29

·

CVE-2008-7103

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Najdi.si Toolbar version 2.0.4.1
Description The issue is related to a stack-based buffer overflow in an ActiveX control. This can be triggered by a long Document.Location property value, potentially allowing remote attackers to cause a denial of service or execute arbitrary code.
Recommendations For Najdi.si Toolbar version 2.0.4.1, consider disabling the ActiveX control in najdisitoolbar.dll as a temporary workaround until a patch is available. Restrict access to the Document.Location property to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7103

Affected Products

Activex
Najdi.Si Toolbar