Vulnerability Description
Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attackers to execute arbitrary code via a long first argument to the Upgrade method. NOTE: some of these details are obtained from third party information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Move Networks Inc | Move Media Player | 1.0.0.1 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/28647Vendor Advisory
- http://www.securityfocus.com/bid/27438Exploit
- http://www.securitytracker.com/id?1019270
- http://www.vupen.com/english/advisories/2008/0274
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39913
- https://www.exploit-db.com/exploits/4979
- http://secunia.com/advisories/28647Vendor Advisory
- http://www.securityfocus.com/bid/27438Exploit
- http://www.securitytracker.com/id?1019270
- http://www.vupen.com/english/advisories/2008/0274
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39913
- https://www.exploit-db.com/exploits/4979
FAQ
What is CVE-2008-0477?
CVE-2008-0477 is a vulnerability with a CVSS score of 10.0 (HIGH). Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attackers to execute arbitrary code via a long first ar...
How severe is CVE-2008-0477?
CVE-2008-0477 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0477?
Check the references section above for vendor advisories and patch information. Affected products include: Move Networks Inc Move Media Player.