20130424 Borland Caliber 11.0 Quiksoft EasyMail SMTP Object Buffer Overflowsmailing list
http://archives.neohapsis.com/archives/bugtraq/2013-04/0220.html CVE-2009-4663
Quiksoft EasyMail 6 - 'AddAttachment' Remote Buffer Overflow
Record summary
CVE-2009-4663 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Heap-based buffer overflow in the Quiksoft EasyMail Objects 6 ActiveX control allows remote attackers to execute arbitrary code via a long argument to the AddAttachment method.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQuiksoft EasyMail 6 - 'AddAttachment' Remote Buffer OverflowExploitDB exploitby bmgsecNot analyzed1 file
References
6bmgsec.com.au
http://www.bmgsec.com.au/advisories/easymail-6-activex-exploit.txt 9705exploit
http://www.exploit-db.com/exploits/9705 36440vdb entry
http://www.securityfocus.com/bid/36440 easymail-addattachment-activex-bo(53325)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/53325 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-4663