CVE-2008-1044
Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QSP2IE) in qsp2ie07076007.dll 7.7.6.7 and qsp2ie07074039.dll 7.7.4.39 in Move Media Player allows remote attackers to execute arbitrary…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QSP2IE) in qsp2ie07076007.dll 7.7.6.7 and qsp2ie07074039.dll 7.7.4.39 in Move Media Player allows remote attackers to execute arbitrary code via a long argument to the UploadLogs method, a different vector than CVE-2007-4722. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.84% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- move networks inc/move media player · move networks inc/qunatum streaming player
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060460.html
- http://secunia.com/advisories/29108Vendor Advisory
- http://www.securityfocus.com/bid/27995
- http://www.vupen.com/english/advisories/2008/0684
- https://www.exploit-db.com/exploits/5190
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060460.html
- http://secunia.com/advisories/29108Vendor Advisory
- http://www.securityfocus.com/bid/27995
- http://www.vupen.com/english/advisories/2008/0684
- https://www.exploit-db.com/exploits/5190
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.