Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Studio Achtundachtzig Subscribe
Filtered by product Bloomooweb Activex Control
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-5658 1 Studio Achtundachtzig 1 Bloomooweb Activex Control 2018-10-17 7.6 HIGH N/A
BlooMooWeb ActiveX control (AidemATL.dll) allows remote attackers to (1) download arbitrary files via a URL in the bstrUrl parameter to the BW_DownloadFile method, (2) execute arbitrary local files via a file path in the bstrParams parameter to the BW_LaunchGame method, and (3) delete arbitrary files via a file path in the filePath parameter to the BW_DeleteTempFile method.