Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-4255


Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."


Published

2008-12-10T14:00:00.970

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft office_frontpage 2002 Yes
Application microsoft project 2003 Yes
Application microsoft project 2007 Yes
Application microsoft project 2007 Yes
Application microsoft visual_basic 6.0 Yes
Application microsoft visual_foxpro 8.0 Yes
Application microsoft visual_foxpro 9.0 Yes
Application microsoft visual_foxpro 9.0 Yes
Application microsoft visual_studio_.net 2002 Yes
Application microsoft visual_studio_.net 2003 Yes

References