Title : BusinessObjects RptViewerAX ActiveX Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2008-0927 CVE ID : CVE-2007-6254
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-19
Technical Description
A vulnerability has been identified in BusinessObjects, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the RptViewerAX ActiveX Control (RptViewerAX.dll) when handling malformed data, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.