CVE-2018-5221 describes multiple buffer overflow vulnerabilities in BarCodeWiz BarCode ActiveX control (BarcodeWiz.DLL) versions prior to 6.7. This flaw allows remote attackers to execute arbitrary code by supplying overly long arguments to the BottomText or TopText properties. With a CVSS score of 8.8 (High), this vulnerability is critical, requiring user interaction but allowing for complete compromise of confidentiality, integrity, and availability. The attack vector is network-based with low attack complexity. Currently, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed in the KEV catalog. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.7CPE matchmatch criteria | cpe:2.3:a:barcodewiz:barcode_activex_control:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.