Lucene search

K
nvd[email protected]NVD:CVE-2008-1490
HistoryMar 25, 2008 - 7:44 p.m.

CVE-2008-1490

2008-03-2519:44:00
CWE-119
web.nvd.nist.gov
2

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.662

Percentile

98.0%

Buffer overflow in a certain Aurigma ActiveX control in ImageUploader4.ocx 4.1.36.0, as used with Piczo (aka Pizco) and possibly other online services, allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long Action property, a different CLSID than CVE-2008-0659.

Affected configurations

Nvd
Node
aurigmaimage_uploader_activex_controlMatch4.1.36.0
OR
piczoimageuploader4Match4.1.36.0
VendorProductVersionCPE
aurigmaimage_uploader_activex_control4.1.36.0cpe:2.3:a:aurigma:image_uploader_activex_control:4.1.36.0:*:*:*:*:*:*:*
piczoimageuploader44.1.36.0cpe:2.3:a:piczo:imageuploader4:4.1.36.0:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.662

Percentile

98.0%