Format string vulnerability in DataRescue Interactive Disassembler and Debugger (IDA) Pro 4.7.0.830 allows remote attackers or local users to cause a denial of service (CPU consumption or application crash) and possibly execute arbitrary code via format string specifiers in a dynamic link library (DLL) name.
http://www.datarescue.com/cgi-local/ultimatebb.cgi?ubb=get_topic%3Bf=2%3Bt=000155%3Bp=0