HIGH · 9.3

CVE-2009-2970

Stack-based buffer overflow in the GetUiDllVersion function in an ActiveX control in UiCheck.dll before 1.0.0.7 in UiTV UiPlayer, as used in BaiduX and other products, allows remote attackers to execu...

Vulnerability Description

Stack-based buffer overflow in the GetUiDllVersion function in an ActiveX control in UiCheck.dll before 1.0.0.7 in UiTV UiPlayer, as used in BaiduX and other products, allows remote attackers to execute arbitrary code via the filename parameter.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
UitvUiplayerAll versions
BaiduBaiduxAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-2970?

CVE-2009-2970 is a vulnerability with a CVSS score of 9.3 (HIGH). Stack-based buffer overflow in the GetUiDllVersion function in an ActiveX control in UiCheck.dll before 1.0.0.7 in UiTV UiPlayer, as used in BaiduX and other products, allows remote attackers to execu...

How severe is CVE-2009-2970?

CVE-2009-2970 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-2970?

Check the references section above for vendor advisories and patch information. Affected products include: Uitv Uiplayer, Baidu Baidux.