peter bassill · operator
$ cve CVE-2008-3430 JSON

CVE-2008-3430 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 5.6% (pctl 93)

Patch early

A public exploit exists.

Description

Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as SiOL Komunikator 1.3, allows remote attackers to execute arbitrary code via a large argument supplied to the BGColor method. NOTE: this might only be a vulnerability in certain insecure configurations of Internet Explorer.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS5.55% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2008-07-31
Last modified2026-06-16

Affected (1)

VendorProduct
eyeball networkseyeball messenger sdk

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD