CVE-2007-6028: Buffer Overflow
Multiple stack-based buffer overflows in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne FlexGrid 7.1 Light allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long string in the (1) Text, (2) EditSelText, (3) EditText, and (4) CellFontName property values.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6028?
CVE-2007-6028 is considered critical due to the potential for remote code execution and denial of service.
How do I fix CVE-2007-6028?
To mitigate CVE-2007-6028, upgrade to a version of ComponentOne FlexGrid that is not vulnerable, or apply any available patches.
What types of attacks can exploit CVE-2007-6028?
CVE-2007-6028 can be exploited via crafted long strings in certain properties, leading to stack-based buffer overflows.
Which software is affected by CVE-2007-6028?
CVE-2007-6028 specifically affects ComponentOne FlexGrid 7.1 Light.
Is CVE-2007-6028 a common vulnerability?
Although CVE-2007-6028 was reported several years ago, the vulnerabilities in ActiveX controls remain relevant in discussions about legacy software security.