CVE-2008-3702 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 9.7% (pctl 95)
Patch early
A public exploit exists.
Description
Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote attackers to execute arbitrary code via a long argument to the (1) ReadGIF or (2) ReadGIF2 method.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 9.73% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-08-15 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| jcomsoft | anigif |
| speedbit | download accelerator plus |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Download Accelerator Plus DAP 8.6 - 'AniGIF.ocx' Buffer Overflow (PoC) | 2008-08-10 |
References
- http://securityreason.com/securityalert/4159
- http://www.securityfocus.com/bid/30621
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44412
- https://www.exploit-db.com/exploits/6216
- http://securityreason.com/securityalert/4159
- http://www.securityfocus.com/bid/30621
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44412
- https://www.exploit-db.com/exploits/6216
→ the Explorer · watch your stack · NVD