CVE-2008-3430 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 5.6% (pctl 93)
Patch early
A public exploit exists.
Description
Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as SiOL Komunikator 1.3, allows remote attackers to execute arbitrary code via a large argument supplied to the BGColor method. NOTE: this might only be a vulnerability in certain insecure configurations of Internet Explorer.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 5.55% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-07-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| eyeball networks | eyeball messenger sdk |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Eyeball MessengerSDK 'CoVideoWindow.ocx' 5.0.907 - ActiveX Control Remote Buffer Overflow | 2008-07-29 |
References
- http://packetstormsecurity.org/0807-exploits/siol-overflow.txt
- http://www.securityfocus.com/bid/30424
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44111
- http://packetstormsecurity.org/0807-exploits/siol-overflow.txt
- http://www.securityfocus.com/bid/30424
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44111
→ the Explorer · watch your stack · NVD