CVE-2008-0437
high · 10Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of these details are obtained from third party information.
10
CVSS
58.1%
EPSS (exploit prob.)
99th
EPSS percentile
2008-01-23
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| hp | virtual_rooms | 1.0.0.100 |
| microsoft | activex | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=full-disclosure&m=120098751528333&w=2
- http://secunia.com/advisories/28595
- http://www.securityfocus.com/bid/27384
- http://www.vupen.com/english/advisories/2008/0236
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39836
- https://www.exploit-db.com/exploits/4959
- http://marc.info/?l=full-disclosure&m=120098751528333&w=2
- http://secunia.com/advisories/28595
- http://www.securityfocus.com/bid/27384
- http://www.vupen.com/english/advisories/2008/0236
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39836
- https://www.exploit-db.com/exploits/4959
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-0437