VulnerabilityModified
CVE-2008-1605
The (1) ltmmCaptureCtrl Class, (2) ltmmConvertCtrl Class, and (3) ltmmPlayCtrl Class ActiveX controls (ltmm15.dll 15.1.0.17 and earlier) in LEADTOOLS Multimedia Toolkit 15 allow attackers to overwrite arbitrary files via the SaveSettingsToFile method.
MEDIUM 6.8EPSS 1.90%
Does this matter?
Lower severity and a low EPSS score (1.90%). Track it; it rarely justifies an emergency change on its own.
Description
The (1) ltmmCaptureCtrl Class, (2) ltmmConvertCtrl Class, and (3) ltmmPlayCtrl Class ActiveX controls (ltmm15.dll 15.1.0.17 and earlier) in LEADTOOLS Multimedia Toolkit 15 allow attackers to overwrite arbitrary files via the SaveSettingsToFile method.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.90% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- leadtools/multimedia toolkit
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29538Vendor Advisory
- http://www.securityfocus.com/bid/28442
- http://www.shinnai.altervista.org/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1206434746.ff.php&page=last
- http://www.shinnai.altervista.org/xplits/TXT_lyyELAFI8pOPu2p7N6cq.htmlExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41467
- http://secunia.com/advisories/29538Vendor Advisory
- http://www.securityfocus.com/bid/28442
- http://www.shinnai.altervista.org/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1206434746.ff.php&page=last
- http://www.shinnai.altervista.org/xplits/TXT_lyyELAFI8pOPu2p7N6cq.htmlExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41467
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.