peter bassill · operator
$ cve CVE-2008-3702 JSON

CVE-2008-3702 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 9.7% (pctl 95)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote attackers to execute arbitrary code via a long argument to the (1) ReadGIF or (2) ReadGIF2 method.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS9.73% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2008-08-15
Last modified2026-06-16

Affected (2)

VendorProduct
jcomsoftanigif
speedbitdownload accelerator plus

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD