Vulnerability Name: | CCN-15743 | ||||||
Published: | 2004-04-06 | ||||||
Updated: | 2004-04-06 | ||||||
Summary: | MSWebDVD ActiveX Control, running on Windows XP Professional, is vulnerable to a denial of service, caused by a buffer overflow in the AcceptParentalLevelChange function. By supplying a long password containing more than 255 characters, a remote attacker could overflow a buffer and cause the ActiveX control to crash. | ||||||
CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||
CVSS v2 Severity: | 6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P)
| ||||||
Vulnerability Consequences: | Denial of Service | ||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Tue Apr 06 2004 - 03:14:31 CDT MSWebDVD Class(mswebdvd.dll) Null Pointer Assignment Source: CCN Type: MSWebDVD ActiveX Control Web page MSWebDVD ActiveX Control Source: CCN Type: BID-10056 Microsoft Internet Explorer MSWebDVD Object Denial of Service Vulnerability Source: XF Type: UNKNOWN mswebdvd-long-password-bo(15743) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |