CVE-2007-3984
Zenturi ProgramChecker - Buffer Overflow via Scan Method in NixonMyPrograms ActiveX Control
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3984. PoCs published by shinnai.
AI-analyzed exploit summary This is a functional exploit for a remote buffer overflow in the Zenturi NixonMyPrograms Class (sasatl.dll v. 1.5.0.531) using heap spray technique to execute arbitrary code (calc.exe). The exploit leverages a vulnerable 'Scan()' method in an ActiveX control.
Description
Buffer overflow in a certain ActiveX control in the NixonMyPrograms class in sasatl.dll 1.5.0.531 in Zenturi ProgramChecker allows remote attackers to execute arbitrary code via a long argument to the Scan method. NOTE: this is probably a different issue than CVE-2007-2987.
Exploits (1)
This is a functional exploit for a remote buffer overflow in the Zenturi NixonMyPrograms Class (sasatl.dll v. 1.5.0.531) using heap spray technique to execute arbitrary code (calc.exe). The exploit leverages a vulnerable 'Scan()' method in an ActiveX control.