10

CVE-2014-1201

Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series with firmware 11.19.85_1FE3A allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the HTTP_PORT parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lorex Technology ≫ Edge Lh310 Firmware Version 7-35-28-1b26e
Lorextechnology ≫ Edge Version lh310
Lorex Technology ≫ Edge3 Lh340 Firmware Version 11.19.85_1fe3a
Lorextechnology ≫ Edge3 Version lh340
Lorex Technology ≫ Edge2 Lh330 Firmware Version 11.17.38-33_1d97a
Lorextechnology ≫ Edge2 Version lh330
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 29.46% 0.979
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://osvdb.org/101903
http://www.securityfocus.com/archive/1/530739/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/90223
https://github.com/pedrib/PoC/blob/master/lorexActivex/lorex-report.txt
https://github.com/pedrib/PoC/blob/master/lorexActivex/lorex-testcase.html