CVE-2010-5193 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 32% (pctl 98)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx) in Viscom Image Viewer CP Pro 8.0 and Gold 6.0 allows remote attackers to execute arbitrary code via a long strDelimit parameter.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 31.97% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-08-31 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| viscomsoft | image viewer cp gold sdk |
| viscomsoft | image viewer cp pro sdk |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Viscom Image Viewer CP Pro 8.0/Gold 6.0 - ActiveX Control (Metasploit) | 2011-11-17 |
| exploit-db | Viscom Image Viewer CP Gold 6 - ActiveX 'TifMergeMultiFiles()' Remote Buffer Overflow | 2010-12-03 |
References
- http://secunia.com/advisories/42445
- http://www.exploit-db.com/exploits/15668
- http://www.exploit-db.com/exploits/18123
- https://exchange.xforce.ibmcloud.com/vulnerabilities/63666
- http://secunia.com/advisories/42445
- http://www.exploit-db.com/exploits/15668
- http://www.exploit-db.com/exploits/18123
- https://exchange.xforce.ibmcloud.com/vulnerabilities/63666
→ the Explorer · watch your stack · NVD