Vulnerability Description
Multiple buffer overflows in BarCodeWiz BarCode before 6.7 ActiveX control (BarcodeWiz.DLL) allow remote attackers to execute arbitrary code via a long argument to the (1) BottomText or (2) TopText property.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Barcodewiz | Barcode Activex Control | < 6.7 |
Related Weaknesses (CWE)
References
- http://hyp3rlinx.altervista.org/advisories/BARCODEWIZ-v6.7-ACTIVEX-COMPONENT-BUFExploitThird Party Advisory
- http://packetstormsecurity.com/files/145731/BarcodeWiz-ActiveX-Control-Buffer-OvExploitThird Party AdvisoryVDB Entry
- http://hyp3rlinx.altervista.org/advisories/BARCODEWIZ-v6.7-ACTIVEX-COMPONENT-BUFExploitThird Party Advisory
- http://packetstormsecurity.com/files/145731/BarcodeWiz-ActiveX-Control-Buffer-OvExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2018-5221?
CVE-2018-5221 is a vulnerability with a CVSS score of 8.8 (HIGH). Multiple buffer overflows in BarCodeWiz BarCode before 6.7 ActiveX control (BarcodeWiz.DLL) allow remote attackers to execute arbitrary code via a long argument to the (1) BottomText or (2) TopText pr...
How severe is CVE-2018-5221?
CVE-2018-5221 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5221?
Check the references section above for vendor advisories and patch information. Affected products include: Barcodewiz Barcode Activex Control.