peter bassill · operator
$ cve CVE-2008-0660 JSON

CVE-2008-0660 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 37.8% (pctl 98)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS37.76% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2008-02-08
Last modified2026-06-16

Affected (3)

VendorProduct
aurigmaimage uploader activex control
facebookfacebook
facebookphotouploader

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD