>> VERITAS Storage Exec DCOM Server Buffer Overflow Vulnerabilities
Title : VERITAS Storage Exec DCOM Server Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2005-1787 CVE ID : CVE-2005-2996 CWE ID : CWE-
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-09-20
Technical Description
Multiple vulnerabilities were identified in VERITAS Storage Exec and VERITAS StorageCentral, which could be exploited by remote attackers to execute arbitrary commands or cause a denial of service. These flaws are due to stack and heap overflow errors in certain ActiveX controls when parsing external input, which could be exploited via a malicious Web site or e-mail message to execute arbitrary commands with privileges of the logged on user.