← All CVEs

CVE-2012-0267

high · 9.3

The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter that triggers use of an arbitrary memory address as a function pointer.

9.3
CVSS
38.5%
EPSS (exploit prob.)
99th
EPSS percentile
2012-01-15
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
ntrglobalntr_activex_control<= 1.1.8

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-0267