Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter.
2012-09-15T17:55:04.800
2025-04-11T00:51:21.963
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | oracle | hyperion_strategic_finance | ≤ 12.0 | Yes |
Application | oracle | hyperion_strategic_finance | 11.1.2.1.0 | Yes |
Application | tidestone | formula_one_activex_control | 6.3.5.1 | Yes |