Vulnerabilities > Sopcast

DATE CVE VULNERABILITY TITLE RISK
2011-12-30 CVE-2011-5044 Permissions, Privileges, and Access Controls vulnerability in Sopcast 3.4.7.45585
SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute arbitrary code by replacing Diagnose.exe with a Trojan horse program.
local
low complexity
sopcast CWE-264
7.2
2009-03-04 CVE-2009-0811 Code Injection vulnerability in Sopcast Sopcore Activex Control 3.0.3.501
Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method.
network
sopcast CWE-94
critical
9.3