Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3) Vivotek RTSP MPEG4 SP Control (RtspVapgDecoderNew.dll 2.0.0.39), and possibly other products, allows remote attackers to execute arbitrary code via a long Url property. NOTE: some of these details are obtained from third party information.
2008-10-28T19:20:14.633
2025-04-09T00:30:58.490
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | 4xem | vatctrl_class | 1.0.0.27 | Yes |
Application | 4xem | vatctrl_class | 1.0.0.51 | Yes |
Application | d-link | mpeg4_shm_audio_control | 1.7.0.5 | Yes |
Application | vivotek | rtsp_mpeg4_sp_control | 2.0.0.39 | Yes |