CVE-2015-0986: Buffer Overflow
Published May 26, 2015
·Updated
Multiple stack-based buffer overflows in Moxa VPort ActiveX SDK Plus before 2.8 allow remote attackers to insert assembly-code lines via vectors involving a regkey (1) set or (2) get command.
Affected Software
1 affected component
MOXA VPort ActiveX SDK Plus<=2.7
Remediation
Patch Available
Event History
May 26, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0986?
CVE-2015-0986 is considered to be a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2015-0986?
To fix CVE-2015-0986, upgrade Moxa VPort ActiveX SDK Plus to version 2.8 or later.
3
What types of attacks can CVE-2015-0986 enable?
CVE-2015-0986 allows remote attackers to execute arbitrary code through crafted commands.
4
What software is affected by CVE-2015-0986?
CVE-2015-0986 affects Moxa VPort ActiveX SDK Plus versions prior to 2.8.
5
How was CVE-2015-0986 discovered?
CVE-2015-0986 was discovered through testing, revealing multiple stack-based buffer overflows.