[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Vulnerability in Microsoft Data Access Components Could Allow Remote Code Execution

ID: oval:org.mitre.oval:def:214Date: (C)2007-02-13   (M)2021-09-11
Class: VULNERABILITYFamily: windows




The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.

Platform:
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Reference:
CVE-2006-5559
CVE    1
CVE-2006-5559
CPE    3
cpe:/o:microsoft:windows_2000::sp4
cpe:/o:microsoft:windows_xp
cpe:/o:microsoft:windows_xp::sp2

© SecPod Technologies