CVE-2008-0660
high · 9.3Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties.
9.3
CVSS
37.8%
EPSS (exploit prob.)
98th
EPSS percentile
2008-02-08
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| aurigma | image_uploader_activex_control | 4.5.70.0 |
| aurigma | image_uploader_activex_control | 4.5.126.0 |
| aurigma | image_uploader_activex_control | 4.6.17.0 |
| aurigma | image_uploader_activex_control | 5.0.10.0 |
| all versions | ||
| photouploader | 4.5.57.0 |
Check a specific version with /api/v1/cve/match.
References
- http://seclists.org/fulldisclosure/2008/Feb/0023.html
- http://secunia.com/advisories/28707
- http://secunia.com/advisories/28713
- http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9060483
- http://www.kb.cert.org/vuls/id/776931
- http://www.securityfocus.com/bid/27576
- http://www.securityfocus.com/bid/27577
- http://www.securitytracker.com/id?1019297
- http://www.vupen.com/english/advisories/2008/0391/references
- http://www.vupen.com/english/advisories/2008/0394/references
- https://www.exploit-db.com/exploits/5049
- http://seclists.org/fulldisclosure/2008/Feb/0023.html
- http://secunia.com/advisories/28707
- http://secunia.com/advisories/28713
- http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9060483
- http://www.kb.cert.org/vuls/id/776931
- http://www.securityfocus.com/bid/27576
- http://www.securityfocus.com/bid/27577
- http://www.securitytracker.com/id?1019297
- http://www.vupen.com/english/advisories/2008/0391/references
- http://www.vupen.com/english/advisories/2008/0394/references
- https://www.exploit-db.com/exploits/5049
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-0660