Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series with firmware 11.19.85_1FE3A allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the HTTP_PORT parameter.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
21 Nov 2024, 02:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/101903 - | |
References | () http://www.securityfocus.com/archive/1/530739/100/0/threaded - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/90223 - | |
References | () https://github.com/pedrib/PoC/blob/master/lorexActivex/lorex-report.txt - | |
References | () https://github.com/pedrib/PoC/blob/master/lorexActivex/lorex-testcase.html - |
Information
Published : 2014-01-15 16:08
Updated : 2024-11-21 02:03
NVD link : CVE-2014-1201
Mitre link : CVE-2014-1201
CVE.ORG link : CVE-2014-1201
JSON object : View
Products Affected
lorex_technology
- edge3_lh340_firmware
- edge\+_lh320_firmware
- edge_lh310_firmware
- edge2_lh330_firmware
lorextechnology
- edge
- edge3
- edge2
- edge\+
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer