peter bassill · operator
$ cve CVE-2008-1472 JSON

CVE-2008-1472 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 39% (pctl 99)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS39.01% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2008-03-24
Last modified2026-06-16

Affected (7)

VendorProduct
computer associatesbrightstor arcserve backup laptops desktops
computer associatesdesktop management suite
computer associatesunicenter dsm r11 list control atx
unicenterasset management
unicenterdesktop management bundle
unicenterremote control
unicentersoftware delivery

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD