sinn3r
d3e57ffc46
Add OSVDB-93754: Synactis PDF In-The-Box ConnectToSynactic Stack Buffer Overflow
...
This module exploits a vulnerability found in Synactis' PDF In-The-Box ActiveX
component, specifically PDF_IN_1.ocx. When a long string of data is given
to the ConnectToSynactis function, which is meant to be used for the ldCmdLine
argument of a WinExec call, a strcpy routine can end up overwriting a TRegistry
class pointer saved on the stack, and results in arbitrary code execution under the
context of the user.
2013-06-06 20:05:08 -05:00
..
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-06-06 20:05:08 -05:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-04-15 15:29:56 -05:00
2013-01-04 00:48:10 +01:00
2013-05-25 13:14:41 +06:00
2013-01-04 00:48:10 +01:00
2013-04-16 20:43:38 -05:00
2013-01-04 00:48:10 +01:00
2013-06-05 02:43:43 -05:00
2013-01-30 23:23:41 -06:00
2013-01-04 00:48:10 +01:00
2013-01-07 11:16:58 -06:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-06-04 18:34:06 -04:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-06-03 14:40:38 -05:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-01-31 14:48:54 -06:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2012-12-22 00:30:09 -06:00
2013-01-04 00:48:10 +01:00
2013-03-30 12:41:31 +01:00
2013-01-04 00:48:10 +01:00
2013-05-31 13:31:36 -05:00
2013-01-04 00:48:10 +01:00
2013-01-16 12:28:09 +01:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-01-04 00:48:10 +01:00
2013-05-16 14:32:02 -05:00
2013-01-04 00:48:10 +01:00