CVE-2013-0501

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
12/04/2013
Last modified:
11/04/2025

Description

The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:cognos_disclosure_management:10.2.0:*:*:*:*:*:*:*