CVE-2009-1092
Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to execute arbitrary code by calling the GetAudioPlayingTime method with certain arguments.
BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/501773/100/0/threaded
MILW0RM: http://www.milw0rm.com/exploits/8206
MISC: http://retrogod.altervista.org/9sg_geovision_liveaudio_freedmem.html
BID: http://www.securityfocus.com/bid/34115
XF: http://xforce.iss.net/xforce/xfdb/49238
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1092
published: 25. 3. 2009