← All CVEs

CVE-2008-1472

high · 9.3

Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.

9.3
CVSS
39.0%
EPSS (exploit prob.)
99th
EPSS percentile
2008-03-24
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
computer_associatesbrightstor_arcserve_backup_laptops_desktops11.5
computer_associatesdesktop_management_suiter11.1
computer_associatesdesktop_management_suiter11.1
computer_associatesdesktop_management_suiter11.1
computer_associatesdesktop_management_suiter11.2
computer_associatesunicenter_dsm_r11_list_control_atx11.2.3.1895
unicenterasset_managementr11.1
unicenterasset_managementr11.1
unicenterasset_managementr11.1
unicenterasset_managementr11.2
unicenterasset_managementr11.2
unicenterasset_managementr11.2
unicenterdesktop_management_bundler11.1
unicenterdesktop_management_bundler11.1
unicenterdesktop_management_bundler11.1
unicenterdesktop_management_bundler11.2
unicenterdesktop_management_bundler11.2
unicenterdesktop_management_bundler11.2
unicenterremote_controlr11.1
unicenterremote_controlr11.1
unicenterremote_controlr11.1
unicenterremote_controlr11.2
unicenterremote_controlr11.2
unicenterremote_controlr11.2
unicentersoftware_deliveryr11.1
unicentersoftware_deliveryr11.1
unicentersoftware_deliveryr11.1
unicentersoftware_deliveryr11.2
unicentersoftware_deliveryr11.2
unicentersoftware_deliveryr11.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-1472