[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-3704Date: (C)2008-08-18   (M)2023-12-22


Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1020710
BID-30674
SECUNIA-31498
EXPLOIT-DB-6244
EXPLOIT-DB-6317
ADV-2008-2380
ADV-2008-3382
MS08-070
TA08-344A
http://support.avaya.com/elmodocs2/security/ASA-2008-473.htm
oval:org.mitre.oval:def:5794
visualstudio-maskededit-bo(44444)

CPE    7
cpe:/a:microsoft:visual_studio:6.0
cpe:/a:microsoft:visual_studio_.net:2003:sp1
cpe:/a:microsoft:visual_studio_.net:2002:sp1
cpe:/a:microsoft:visual_foxpro:8.0:sp1
...
CWE    1
CWE-119
OVAL    2
oval:org.secpod.oval:def:3093
oval:org.mitre.oval:def:5794

© SecPod Technologies