CVE-2006-6488: Buffer Overflow
Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX, allows remote attackers to execute arbitrary code via a long (1) FileName or (2) Filter argument.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6488?
CVE-2006-6488 is classified as a critical vulnerability due to its ability to allow remote attackers to execute arbitrary code.
How do I fix CVE-2006-6488?
To fix CVE-2006-6488, upgrade the Dialog Wrapper Module ActiveX control to version 8.4.166.0 or later.
What type of vulnerability is CVE-2006-6488?
CVE-2006-6488 is a stack-based buffer overflow vulnerability affecting the Dialog Wrapper Module ActiveX control.
Who is affected by CVE-2006-6488?
Users of the ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX that utilize the affected version of the Dialog Wrapper Module are at risk from CVE-2006-6488.
What can an attacker do with CVE-2006-6488?
An attacker exploiting CVE-2006-6488 can execute arbitrary code on the victim's machine by providing specially crafted input.