CVE-2006-6488 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 7.9% (pctl 95)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX, allows remote attackers to execute arbitrary code via a long (1) FileName or (2) Filter argument.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 7.9% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| iconics | dialog wrapper module activex control |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ICONICS Vessel / Gauge / Switch 8.02.140 - ActiveX Buffer Overflow (Metasploit) | 2008-09-25 |
References
- http://osvdb.org/32552
- http://secunia.com/advisories/23583
- http://www.kb.cert.org/vuls/id/251969
- http://www.securityfocus.com/bid/21849
- http://www.vupen.com/english/advisories/2007/0025
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31228
- http://osvdb.org/32552
- http://secunia.com/advisories/23583
- http://www.kb.cert.org/vuls/id/251969
- http://www.securityfocus.com/bid/21849
- http://www.vupen.com/english/advisories/2007/0025
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31228
→ the Explorer · watch your stack · NVD