CVE-2010-5194 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 6.3% (pctl 93)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the Image2PDF function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx) in Viscom Image Viewer CP Pro 8.0, Gold 5.5, Gold 6.0, and earlier allows remote attackers to execute arbitrary code via a long strPDFFile parameter.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 6.34% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-08-31 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| viscomsoft | image viewer cp gold sdk |
| viscomsoft | image viewer cp pro sdk |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Viscom Image Viewer CP Pro 8.0/Gold 6.0 - ActiveX Control (Metasploit) | 2011-11-17 |
| exploit-db | Viscom Image Viewer CP Gold 5.5 - 'Image2PDF()' Remote Buffer Overflow (Metasploit) | 2010-12-02 |
References
- http://secunia.com/advisories/42445
- http://www.exploit-db.com/exploits/15658
- http://www.osvdb.org/69566
- https://exchange.xforce.ibmcloud.com/vulnerabilities/63642
- http://secunia.com/advisories/42445
- http://www.exploit-db.com/exploits/15658
- http://www.osvdb.org/69566
- https://exchange.xforce.ibmcloud.com/vulnerabilities/63642
→ the Explorer · watch your stack · NVD