← All CVEs

CVE-2008-0660

high · 9.3

Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties.

9.3
CVSS
37.8%
EPSS (exploit prob.)
98th
EPSS percentile
2008-02-08
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
aurigmaimage_uploader_activex_control4.5.70.0
aurigmaimage_uploader_activex_control4.5.126.0
aurigmaimage_uploader_activex_control4.6.17.0
aurigmaimage_uploader_activex_control5.0.10.0
facebookfacebookall versions
facebookphotouploader4.5.57.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-0660