CVE-2011-5167

Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:hyperion_strategic_finance:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:hyperion_strategic_finance:11.1.2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:tidestone:formula_one_activex_control:6.3.5.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2012-09-15 17:55

Updated : 2024-02-04 18:16


NVD link : CVE-2011-5167

Mitre link : CVE-2011-5167

CVE.ORG link : CVE-2011-5167


JSON object : View

Products Affected

oracle

  • hyperion_strategic_finance

tidestone

  • formula_one_activex_control
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer