CVE-2008-4384
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) enableZoomPastMax methods.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 28.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) enableZoomPastMax methods.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 28.71% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- iseemedia/lpviewer · mgi software/lpviewer · roxio/lpviewer
- Source
- cret@cert.org
References
- http://secunia.com/advisories/32140Vendor Advisory
- http://www.kb.cert.org/vuls/id/848873US Government Resource
- http://www.securityfocus.com/bid/31604
- http://www.vupen.com/english/advisories/2008/2749
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45699
- http://secunia.com/advisories/32140Vendor Advisory
- http://www.kb.cert.org/vuls/id/848873US Government Resource
- http://www.securityfocus.com/bid/31604
- http://www.vupen.com/english/advisories/2008/2749
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45699
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.