Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.
Use CWE-119, Advantech vendor hub and Advantech Studio product page to widen CVE-2011-0340 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2011-0488 and CVE-2013-1627 for nearby disclosures in the same product family.