CVE-2008-1044 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 4.8% (pctl 92)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QSP2IE) in qsp2ie07076007.dll 7.7.6.7 and qsp2ie07074039.dll 7.7.4.39 in Move Media Player allows remote attackers to execute arbitrary code via a long argument to the UploadLogs method, a different vector than CVE-2007-4722. NOTE: some of these details are obtained from third party information.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 4.84% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-02-27 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| move networks inc | move media player |
| move networks inc | qunatum streaming player |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Move Networks Quantum Streaming Player Control - Remote Buffer Overflow | 2008-02-26 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060460.html
- http://secunia.com/advisories/29108
- http://www.securityfocus.com/bid/27995
- http://www.vupen.com/english/advisories/2008/0684
- https://www.exploit-db.com/exploits/5190
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060460.html
- http://secunia.com/advisories/29108
- http://www.securityfocus.com/bid/27995
- http://www.vupen.com/english/advisories/2008/0684
- https://www.exploit-db.com/exploits/5190
→ the Explorer · watch your stack · NVD