8.5 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:S/C:C/I:C/A:C
7.5 High
AI Score
Confidence
High
0.965 High
EPSS
Percentile
99.6%
Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allow remote attackers to execute arbitrary code via crafted (1) Rows and (2) Cols properties to the (a) ExpandAll and (b) CollapseAll methods, related to access of incorrectly initialized objects and corruption of the “system state,” aka “Hierarchical FlexGrid Control Memory Corruption Vulnerability.”
secunia.com/secunia_research/2007-72/
support.avaya.com/elmodocs2/security/ASA-2008-473.htm
www.securityfocus.com/archive/1/499059/100/0/threaded
www.securitytracker.com/id?1021369
www.us-cert.gov/cas/techalerts/TA08-344A.html
www.vupen.com/english/advisories/2008/3382
docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-070
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5805