CVE-2008-1472
high · 9.3Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.
9.3
CVSS
39.0%
EPSS (exploit prob.)
99th
EPSS percentile
2008-03-24
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| computer_associates | brightstor_arcserve_backup_laptops_desktops | 11.5 |
| computer_associates | desktop_management_suite | r11.1 |
| computer_associates | desktop_management_suite | r11.1 |
| computer_associates | desktop_management_suite | r11.1 |
| computer_associates | desktop_management_suite | r11.2 |
| computer_associates | unicenter_dsm_r11_list_control_atx | 11.2.3.1895 |
| unicenter | asset_management | r11.1 |
| unicenter | asset_management | r11.1 |
| unicenter | asset_management | r11.1 |
| unicenter | asset_management | r11.2 |
| unicenter | asset_management | r11.2 |
| unicenter | asset_management | r11.2 |
| unicenter | desktop_management_bundle | r11.1 |
| unicenter | desktop_management_bundle | r11.1 |
| unicenter | desktop_management_bundle | r11.1 |
| unicenter | desktop_management_bundle | r11.2 |
| unicenter | desktop_management_bundle | r11.2 |
| unicenter | desktop_management_bundle | r11.2 |
| unicenter | remote_control | r11.1 |
| unicenter | remote_control | r11.1 |
| unicenter | remote_control | r11.1 |
| unicenter | remote_control | r11.2 |
| unicenter | remote_control | r11.2 |
| unicenter | remote_control | r11.2 |
| unicenter | software_delivery | r11.1 |
| unicenter | software_delivery | r11.1 |
| unicenter | software_delivery | r11.1 |
| unicenter | software_delivery | r11.2 |
| unicenter | software_delivery | r11.2 |
| unicenter | software_delivery | r11.2 |
Check a specific version with /api/v1/cve/match.
References
- http://community.ca.com/blogs/casecurityresponseblog/archive/2008/3/28.aspx
- http://secunia.com/advisories/29408
- http://www.securityfocus.com/archive/1/489893/100/0/threaded
- http://www.securityfocus.com/archive/1/490263/100/0/threaded
- http://www.securityfocus.com/bid/28268
- http://www.securitytracker.com/id?1019617
- http://www.vupen.com/english/advisories/2008/0902/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41225
- https://www.exploit-db.com/exploits/5264
- http://community.ca.com/blogs/casecurityresponseblog/archive/2008/3/28.aspx
- http://secunia.com/advisories/29408
- http://www.securityfocus.com/archive/1/489893/100/0/threaded
- http://www.securityfocus.com/archive/1/490263/100/0/threaded
- http://www.securityfocus.com/bid/28268
- http://www.securitytracker.com/id?1019617
- http://www.vupen.com/english/advisories/2008/0902/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41225
- https://www.exploit-db.com/exploits/5264
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-1472