CVE-2015-8561
published 2015-12-15CVE-2015-8561: The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remote attackers to execute arbitrary code or cause a denial of…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.83%
88.9th percentile
The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted integer value to the (1) AttachToSS, (2) CopyAll, (3) CopyRange, (4) CopyRangeEx, or (5) SwapTable method, a different vulnerability than CVE-2015-7918.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | proclima | <= 6.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vxpx-99jp-v96v: Multiple buffer overflows in the F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-7918 [MEDIUM] CWE-119 GHSA-vxpx-99jp-v96v: Multiple buffer overflows in the F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6
Multiple buffer overflows in the F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allow remote attackers to execute arbitrary code via the (1) Attach, (2) DefinedName, (3) DefinedNameLocal, (4) ODBCPrepareEx, (5) ObjCreatePolygon, (6) SetTabbedTextEx, or (7) SetValidationRule method, a different vulnerability than CVE-2015-8561.
GHSA
GHSA-8jw8-h794-x973: The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-8561 [MEDIUM] CWE-119 GHSA-8jw8-h794-x973: The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6
The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted integer value to the (1) AttachToSS, (2) CopyAll, (3) CopyRange, (4) CopyRangeEx, or (5) SwapTable method, a different vulnerability than CVE-2015-7918.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-329-01http://www.zerodayinitiative.com/advisories/ZDI-15-626http://www.zerodayinitiative.com/advisories/ZDI-15-627http://www.zerodayinitiative.com/advisories/ZDI-15-628http://www.zerodayinitiative.com/advisories/ZDI-15-629https://ics-cert.us-cert.gov/advisories/ICSA-15-335-02http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-329-01http://www.zerodayinitiative.com/advisories/ZDI-15-626http://www.zerodayinitiative.com/advisories/ZDI-15-627http://www.zerodayinitiative.com/advisories/ZDI-15-628http://www.zerodayinitiative.com/advisories/ZDI-15-629https://ics-cert.us-cert.gov/advisories/ICSA-15-335-02
2015-12-15
Published