Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft OLE自动化SubstringData函数堆溢出漏洞(MS07-043)
Vulnerability Description
Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。 Windows OLE机制的实现上存在整数溢出漏洞,远程攻击者可能利用此漏洞控制用户系统。 对象链接和嵌入(OLE)自动化是一个Windows协议,允许应用程序共享数据或控制其他应用程序。在使用OLE自动化时如果向TextNode JavaScript对象的substringData()方式传送了特制参数的话,就可能触发整数溢出,导致错误的内存分配。如果在实例化了不同的ActiveX对象后出现上述情况的话,则在解
CVSS Information
N/A
Vulnerability Type
N/A