Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=110616221411579&w=2 | issue tracking mailing list third party advisory |
http://www.kb.cert.org/vuls/id/673134 | third party advisory us government resource |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17714 | vdb entry third party advisory |
http://www.securityfocus.com/bid/11367 | vdb entry third party advisory |
http://www.ngssoftware.com/advisories/heartbeatfull.txt | broken link |