AwingSoft Web3D Player ActiveX Control Buffer Overflow

Strike ID:
E13-uv201
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2013

Description

This strike identifies a buffer overflow vulnerability in Winds3D Viewer. An activeX control does not properly validate the value passed to the SceneURL parameter. An overly long value passed to SceneURL will overflow the buffer.

CVE