High severity8.8NVD Advisory· Published Nov 10, 2017· Updated Jun 17, 2026
CVE-2017-12969
CVE-2017-12969
Description
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:avaya:ip_office_contact_center:10.0:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:avaya:ip_office_contact_center:10.0:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office_contact_center:10.0.0.3-8600.1705:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office_contact_center:10.1:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office_contact_center:9.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office_contact_center:9.1.0.2209.1540:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office_contact_center:9.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office_contact_center:9.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office_contact_center:9.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office_contact_center:9.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:avaya:ip_office_contact_center:9.1:sp11:*:*:*:*:*:*
- (no CPE)range: <10.1.1
- Range: <10.1.1
Patches
Vulnerability mechanics
References
6- downloads.avaya.com/css/P8/documents/101044091nvdVendor Advisory
- packetstormsecurity.com/files/144882/Avaya-IP-Office-IPO-10.1-Active-X-Buffer-Overflow.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2017/Nov/17nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/101667nvdThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/43120/nvdThird Party AdvisoryVDB Entry
- hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-%28IPO%29-v9.1.0-10.1-VIEWERCTRL-ACTIVE-X-BUFFER-OVERFLOW-0DAY.txtnvd
News mentions
0No linked articles in our index yet.