CVE-2007-6189

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
30/11/2007
Last modified:
09/04/2025

Description

A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%%" sequence, which is misinterpreted as a Unicode string and decoded twice, leading to improper memory allocation and a heap-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bitdefender:online_anti-virus_scanner:8.0:*:*:*:*:*:*:*