{
    "id": "CVE-2006-6488",
    "published": "2006-12-31 05:00:00",
    "last_modified": "2026-06-16 22:33:13",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
    "cwe": null,
    "description": "Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX, allows remote attackers to execute arbitrary code via a long (1) FileName or (2) Filter argument.",
    "epss_score": "0.07900",
    "epss_percentile": "0.94554",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-04 18:17:05",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "iconics",
            "product": "dialog_wrapper_module_activex_control"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "6570",
            "title": "ICONICS Vessel / Gauge / Switch 8.02.140 - ActiveX Buffer Overflow (Metasploit)",
            "date": "2008-09-25",
            "url": "https://www.exploit-db.com/exploits/6570"
        }
    ],
    "refs_list": [
        "http://osvdb.org/32552",
        "http://secunia.com/advisories/23583",
        "http://www.kb.cert.org/vuls/id/251969",
        "http://www.securityfocus.com/bid/21849",
        "http://www.vupen.com/english/advisories/2007/0025",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/31228",
        "http://osvdb.org/32552",
        "http://secunia.com/advisories/23583",
        "http://www.kb.cert.org/vuls/id/251969",
        "http://www.securityfocus.com/bid/21849",
        "http://www.vupen.com/english/advisories/2007/0025",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/31228"
    ]
}