This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Microsoft First view 2002-10-04
Product Visual Foxpro Last view 2012-08-14
Version Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:microsoft:visual_foxpro:8.0:sp1:*:*:*:*:*:* 8
cpe:2.3:a:microsoft:visual_foxpro:9.0:sp2:*:*:*:*:*:* 8
cpe:2.3:a:microsoft:visual_foxpro:9.0:sp1:*:*:*:*:*:* 6
cpe:2.3:a:microsoft:visual_foxpro:6.0:*:*:*:*:*:*:* 4

Related : CVE

  Date Alert Description
9.3 2012-08-14 CVE-2012-1856

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."

9.3 2012-04-10 CVE-2012-0158

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in the wild in April 2012, aka "MSCOMCTL.OCX RCE Vulnerability."

8.5 2008-12-10 CVE-2008-4256

The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "Charts Control Memory Corruption Vulnerability."

9.3 2008-12-10 CVE-2008-4255

Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."

8.5 2008-12-10 CVE-2008-4254

Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allow remote attackers to execute arbitrary code via crafted (1) Rows and (2) Cols properties to the (a) ExpandAll and (b) CollapseAll methods, related to access of incorrectly initialized objects and corruption of the "system state," aka "Hierarchical FlexGrid Control Memory Corruption Vulnerability."

8.5 2008-12-10 CVE-2008-4253

The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."

8.5 2008-12-10 CVE-2008-4252

The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "DataGrid Control Memory Corruption Vulnerability."

9.3 2008-08-18 CVE-2008-3704

Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."

5.8 2008-01-10 CVE-2008-0236

An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd method.

7.5 2007-10-09 CVE-2007-5322

Insecure method vulnerability in the FPOLE.OCX 6.0.8450.0 ActiveX control in Microsoft Visual FoxPro 6.0 allows remote attackers to execute arbitrary programs by specifying them as an argument to the FoxDoCmd function.

7.5 2007-09-10 CVE-2007-4790

Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library; and Internet Explorer 5.01, 6 SP1 and SP2, and 7; allows remote attackers to execute arbitrary code via a long first argument to the FoxDoCmd function.

7.5 2002-10-04 CVE-2002-0696

Microsoft Visual FoxPro 6.0 does not register its associated files with Internet Explorer, which allows remote attackers to execute Visual FoxPro applications without warning via HTML that references specially-crafted filenames.

CWE : Common Weakness Enumeration

%idName
30% (3) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
20% (2) CWE-399 Resource Management Errors
20% (2) CWE-94 Failure to Control Generation of Code ('Code Injection')
10% (1) CWE-264 Permissions, Privileges, and Access Controls
10% (1) CWE-189 Numeric Errors
10% (1) CWE-78 Improper Sanitization of Special Elements used in an OS Command ('O...

Oval Markup Language : Definitions

OvalID Name
oval:org.mitre.oval:def:5481 ActiveX Object Memory Corruption Vulnerability
oval:org.mitre.oval:def:5794 Masked Edit Control Memory Corruption Vulnerability
oval:org.mitre.oval:def:5894 DataGrid Control Memory Corruption Vulnerability
oval:org.mitre.oval:def:5994 FlexGrid Control Memory Corruption Vulnerability
oval:org.mitre.oval:def:5805 Hierarchical FlexGrid Control Memory Corruption Vulnerability
oval:org.mitre.oval:def:6032 Windows Common AVI Parsing Overflow Vulnerability
oval:org.mitre.oval:def:5651 Charts Control Memory Corruption Vulnerability
oval:org.mitre.oval:def:15462 MSCOMCTL.OCX RCE Vulnerability
oval:org.mitre.oval:def:15447 MSCOMCTL.OCX RCE Vulnerability - MS12-060

SAINT Exploits

Description Link
Microsoft Visual Studio MaskedEdit ActiveX buffer overflow More info here
Microsoft Windows Common Controls MSCOMCTL.OCX Vulnerability More info here
Visual FoxPro vfp6r.dll ActiveX Control DoCmd command execution More info here

Open Source Vulnerability Database (OSVDB)

id Description
50581 Microsoft Visual Basic Charts Control ActiveX (Mschrt20.ocx) Unspecified Memo...
50580 Microsoft Visual Basic Animation ActiveX (mscomct2.ocx) AVI Parsing Memory Co...
50579 Microsoft Visual Basic Hierarchical FlexGrid ActiveX (mshflxgd.ocx) Multiple ...
50578 Microsoft Visual Basic FlexGrid ActiveX (msflxgrd.ocx) Unspecified Memory Cor...
50577 Microsoft Visual Basic DataGrid ActiveX (msdatgrd.ocx) Unspecified Memory Cor...
47475 Microsoft Visual Studio Masked Edit Control ActiveX (Msmask32.ocx) Mask Param...
41468 Microsoft FoxPro ActiveX Web Page Parsing Unspecified Memory Corruption
40380 Microsoft Visual FoxPro ActiveX (vfp6r.dll) DoCmd Method Arbitrary Command Ex...
38487 Microsoft Visual FoxPro ActiveX (FPOLE.OCX) FoxDoCmd Function Arbitrary Comma...
7897 Microsoft IE Crafted Filename Arbitrary Visual FoxPro Application Execution

ExploitDB Exploits

id Description
7431 Microsoft Visual Basic ActiveX Controls mscomct2.ocx Buffer Overflow PoC

OpenVAS Exploits

id Description
2012-08-15 Name : Microsoft Windows Common Controls Remote Code Execution Vulnerability (2720573)
File : nvt/secpod_ms12-060.nasl
2012-04-11 Name : Microsoft Windows Common Controls Remote Code Execution Vulnerability (2664258)
File : nvt/secpod_ms12-027.nasl

Information Assurance Vulnerability Management (IAVM)

id Description
2012-A-0132 Microsoft Windows Common Controls Remote Code Execution Vulnerability
Severity: Category II - VMSKEY: V0033659
2012-A-0059 Microsoft Windows Common Controls Remote Code Execution Vulnerability
Severity: Category II - VMSKEY: V0031982
2009-B-0009 Microsoft Security Update of ActiveX Kill Bits
Severity: Category I - VMSKEY: V0018406
2008-A-0088 Multiple Vulnerabilities in Microsoft Visual Basic 6.0
Severity: Category II - VMSKEY: V0017907

Snort® IPS/IDS

This CPE Product have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
Date Description
2019-04-18 Microsoft Office MSCOMCTL ActiveX control tabstrip method attempt
RuleID : 49496 - Type : FILE-OFFICE - Revision : 1
2019-04-18 Microsoft Office MSCOMCTL ActiveX control tabstrip method attempt
RuleID : 49494 - Type : FILE-OFFICE - Revision : 1
2017-09-19 RTF obfuscation string
RuleID : 43990 - Type : INDICATOR-OBFUSCATION - Revision : 3
2017-09-19 newlines embedded in rtf header
RuleID : 43989 - Type : INDICATOR-OBFUSCATION - Revision : 3
2016-03-14 Microsoft Visual FoxPro ActiveX clsid access
RuleID : 36792 - Type : BROWSER-PLUGINS - Revision : 2
2015-09-03 Microsoft Windows Visual Basic Charts ActiveX function call access
RuleID : 35423 - Type : BROWSER-PLUGINS - Revision : 3
2015-01-20 Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt
RuleID : 32863 - Type : FILE-OFFICE - Revision : 4
2015-01-20 Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt
RuleID : 32862 - Type : FILE-OFFICE - Revision : 3
2015-01-20 Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt
RuleID : 32861 - Type : FILE-OFFICE - Revision : 2
2015-01-20 Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt
RuleID : 32860 - Type : FILE-OFFICE - Revision : 2
2015-01-20 Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt
RuleID : 32859 - Type : FILE-OFFICE - Revision : 2
2015-01-20 Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt
RuleID : 32858 - Type : FILE-OFFICE - Revision : 2
2015-01-20 Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt
RuleID : 32857 - Type : FILE-OFFICE - Revision : 2
2014-11-16 Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt
RuleID : 31927 - Type : FILE-OFFICE - Revision : 2
2014-11-16 Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt
RuleID : 31926 - Type : FILE-OFFICE - Revision : 2
2014-11-16 Win.Trojan.Otupsys variant outbound connection
RuleID : 31716 - Type : MALWARE-CNC - Revision : 2
2014-06-14 Shiqiang Gang malicious XLS targeted attack detection
RuleID : 30991 - Type : MALWARE-CNC - Revision : 6
2014-06-14 Shiqiang Gang malicious XLS targeted attack detection
RuleID : 30990 - Type : MALWARE-CNC - Revision : 5
2014-06-14 DNS request for known malware domain help.2012hi.hk
RuleID : 30989 - Type : BLACKLIST - Revision : 3
2014-05-01 multiple binary tags in close proximity - potentially malicious
RuleID : 30328 - Type : INDICATOR-OBFUSCATION - Revision : 3
2014-05-01 multiple binary tags in close proximity - potentially malicious
RuleID : 30327 - Type : INDICATOR-OBFUSCATION - Revision : 3
2014-04-12 Microsoft Windows common controls stack buffer overflow via malicious toolbar...
RuleID : 30166 - Type : FILE-OFFICE - Revision : 2
2014-04-12 Microsoft Windows common controls stack buffer overflow via malicious toolbar...
RuleID : 30165 - Type : FILE-OFFICE - Revision : 2
2014-04-12 Microsoft Windows common controls stack buffer overflow via malicious MSComct...
RuleID : 30164 - Type : FILE-OFFICE - Revision : 2
2014-04-12 Microsoft Windows common controls stack buffer overflow via malicious MSComct...
RuleID : 30163 - Type : FILE-OFFICE - Revision : 2

Nessus® Vulnerability Scanner

id Description
2012-08-15 Name: The remote Windows host has a code execution vulnerability.
File: smb_nt_ms12-060.nasl - Type: ACT_GATHER_INFO
2012-04-11 Name: The remote Windows host is affected by a remote code execution vulnerability.
File: smb_nt_ms12-027.nasl - Type: ACT_GATHER_INFO
2009-02-11 Name: The remote Windows host is missing a security update containing ActiveX kill ...
File: smb_kb_960715.nasl - Type: ACT_GATHER_INFO
2008-12-10 Name: Arbitrary code can be executed on the remote host through the web client.
File: smb_nt_ms08-070.nasl - Type: ACT_GATHER_INFO
2008-02-12 Name: Arbitrary code can be executed on the remote host through the web client.
File: smb_nt_ms08-010.nasl - Type: ACT_GATHER_INFO