CVE-2008-3430
Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as SiOL Komunikator 1.3, allows remote attackers to execute arbitrary code via a large argument supplied to the BGColor method.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as SiOL Komunikator 1.3, allows remote attackers to execute arbitrary code via a large argument supplied to the BGColor method. NOTE: this might only be a vulnerability in certain insecure configurations of Internet Explorer.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 5.55% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- eyeball networks/eyeball messenger sdk
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/0807-exploits/siol-overflow.txtExploit
- http://www.securityfocus.com/bid/30424Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44111
- http://packetstormsecurity.org/0807-exploits/siol-overflow.txtExploit
- http://www.securityfocus.com/bid/30424Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44111
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.