Vulnerabilities > CVE-2010-0766 - Numeric Errors vulnerability in Luxology Modo 401

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
luxology
CWE-189
critical

Summary

Integer overflow in the Swap4 function in valet4.dll in Luxology Modo 401 allows user-assisted remote attackers to execute arbitrary code via a .LXO file containing a CHNL subchunk associated with an invalid length.

Vulnerable Configurations

Part Description Count
Application
Luxology
1

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/86852/CORE-2009-0913.txt
idPACKETSTORM:86852
last seen2016-12-05
published2010-03-03
reporterCore Security Technologies
sourcehttps://packetstormsecurity.com/files/86852/Core-Security-Technologies-Advisory-2009.0913.html
titleCore Security Technologies Advisory 2009.0913