Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2008-0956 | First vendor Publication | 2008-06-11 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInstActivator.dll in BackWeb before 8.1.1.87, as used in Logitech Desktop Manager (LDM) before 2.56, allow remote attackers to execute arbitrary code via unspecified vectors. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0956 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OpenVAS Exploits
Date | Description |
---|---|
2011-01-10 | Name : Microsoft Windows Speech Components Voice Recognition Command Execution Vulne... File : nvt/gb_ms08-032.nasl |
2008-09-30 | Name : Bluetooth Stack Could Allow Remote Code Execution Vulnerability (951376) File : nvt/gb_ms08-030.nasl |
2008-09-30 | Name : Vulnerabilities in DirectX Could Allow Remote Code Execution (951698) File : nvt/gb_ms08-033.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
46087 | Logitech Desktop Messenger BackWeb ActiveX Unspecified Overflow |
46076 | BackWeb Lite Install Runner LiteInstActivator.dll ActiveX (LiteInstActivator.... |
Snort® IPS/IDS
Date | Description |
---|---|
2016-03-14 | Microsoft Internet Explorer sapi.dll ActiveX clsid access attempt RuleID : 36434 - Revision : 2 - Type : BROWSER-PLUGINS |
2016-03-14 | Microsoft Internet Explorer sapi.dll ActiveX clsid access attempt RuleID : 36433 - Revision : 2 - Type : BROWSER-PLUGINS |
2014-01-10 | backweb ActiveX clsid unicode access RuleID : 13833 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Internet Explorer backweb ActiveX clsid access RuleID : 13832 - Revision : 11 - Type : BROWSER-PLUGINS |
2014-01-10 | sapi.dll alternate killbit ActiveX clsid unicode access RuleID : 13831 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Internet Explorer sapi.dll ActiveX clsid access attempt RuleID : 13830 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | sapi.dll ActiveX clsid unicode access RuleID : 13829 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Internet Explorer sapi.dll ActiveX clsid access attempt RuleID : 13828 - Revision : 12 - Type : BROWSER-PLUGINS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2008-06-10 | Name : The remote Windows host has an ActiveX control that is affected by multiple m... File : smb_nt_ms08-032.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:14:11 |
|
2024-11-28 12:14:59 |
|
2024-02-14 13:28:25 |
|
2021-04-22 01:07:34 |
|
2020-05-23 01:39:09 |
|
2020-05-23 00:21:19 |
|
2018-10-13 00:22:38 |
|
2017-08-08 09:23:52 |
|
2016-04-26 17:09:26 |
|
2014-02-17 10:43:52 |
|
2013-05-11 00:10:10 |
|