Overview
Description
The HHOpen ActiveX control (hhopen.ocx) has a buffer overflow in the OpenHelp method. Because the control is marked safe-for-scripting, an attacker may be able to script this control and exploit the vulnerability when you visit a web page. The classID for the vulnerable control is: {130D7743-5F5A-11D1-B676-00A0C9697233}. |
Impact
An attacker may be able to exploit a buffer overflow in the HHOpen ActiveX control and execute arbitrary code on the system of the person visiting a malicious web page. |
Solution
Apply a patch |
Disable "Script ActiveX controls marked safe for scripting" |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This document was written by Cory F Cohen.
Other Information
CVE IDs: | CVE-1999-0702 |
Severity Metric: | 12.66 |
Date Public: | 1999-09-10 |
Date First Published: | 2000-10-31 |
Date Last Updated: | 2000-11-01 15:08 UTC |
Document Revision: | 10 |