CVE-2008-0437
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 58.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 58.08% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- hp/virtual rooms · microsoft/activex
- Source
- cve@mitre.org
References
- http://marc.info/?l=full-disclosure&m=120098751528333&w=2
- http://secunia.com/advisories/28595Vendor Advisory
- http://www.securityfocus.com/bid/27384
- http://www.vupen.com/english/advisories/2008/0236
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39836
- https://www.exploit-db.com/exploits/4959
- http://marc.info/?l=full-disclosure&m=120098751528333&w=2
- http://secunia.com/advisories/28595Vendor Advisory
- http://www.securityfocus.com/bid/27384
- http://www.vupen.com/english/advisories/2008/0236
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39836
- https://www.exploit-db.com/exploits/4959
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.