Title : Newtone ImageKit ActiveX Controls Multiple Client-Side Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2006-4794 CVE ID : CVE-2006-3893
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-11-30
Technical Description
Multiple vulnerabilities have been identified in various Newtone ImageKit ActiveX controls, which could be exploited by attackers to take complete control of an affected system. These flaws are due to buffer overflow errors when passing specially crafted arguments to certain methods, which could be exploited by remote attackers to execute arbitrary commands by tricking a user into visiting a malicious web page.