VulnerabilityModified
CVE-2015-5624
Buffer overflow in the ExecCall method in c2lv6.ocx in the FreeBit ELPhoneBtnV6 ActiveX control allows remote attackers to execute arbitrary code via a crafted HTML document, related to the discontinued "Click to Live" service.
MEDIUM 6.8EPSS 2.32%
Does this matter?
Lower severity and a low EPSS score (2.32%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in the ExecCall method in c2lv6.ocx in the FreeBit ELPhoneBtnV6 ActiveX control allows remote attackers to execute arbitrary code via a crafted HTML document, related to the discontinued "Click to Live" service.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.32% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- freebit/elphonebtnv6 activex control
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN62078684/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000127Vendor Advisory
- http://jvn.jp/en/jp/JVN62078684/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000127Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.