[Japanese] | |
JVNDB-2015-000127 | |
ELPhoneBtnV6 ActiveX control vulnerable to buffer overflow | |
Overview | |
ELPhoneBtnV6 ActiveX control was used for "Click to Live" service provided by FreeBit Co., Ltd. Although "Click to Live" service has been discontinued, PCs that used the "Click to Live" service may still have the ActiveX control installed. | |
CVSS Severity (What is CVSS?) | |
CVSS V2 Severity:
Base Metrics 6.8 (Medium) [IPA Score]
| |
Affected Products | |
| |
FreeBit Co., Ltd. | |
| |
Impact | |
By convincing a user to view a specially crafted HTML document (e.g., a web page, an HTML email message, or an HTML email attachment), an attacker may be able to execute arbitrary code with the privileges of the user. | |
Solution | |
[Delete the ELPhoneBtnV6] | |
Vendor Information | |
FreeBit Co., Ltd. | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2015/09/07 |
Date First Published | 2015/09/07 |
Date Last Updated | 2015/09/09 |