Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflow in the DownloadCertificateExt function in SignKorea SKCommAX ActiveX control module 7.2.0.2 and 3280 6.6.0.1 allows remote attackers to execute arbitrary code via a long pszUserID argument.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SignKorea SKCommAX ActiveX控件远程溢出漏洞
Vulnerability Description
SKCommAX的ActiveX控件是韩国银行、股票等在线银行服务常用的证书解决方案。 SKCommAX ActiveX控件的DownloadCertificateExt()函数没有正确验证UserID参数,如果用户访问了恶意站点的话就可能会触发缓冲区溢出,导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A