CVE-2008-3878 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 36.2% (pctl 98)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 36.23% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-09-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ultrashareware | ultra office control |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ultra Shareware Office Control - ActiveX HttpUpload Buffer Overflow (Metasploit) | 2010-09-20 |
| exploit-db | Ultra Shareware Office Control - ActiveX Control Remote Buffer Overflow | 2008-08-27 |
References
- http://secunia.com/advisories/31632
- http://securityreason.com/securityalert/4200
- http://www.securityfocus.com/bid/30861
- http://www.shinnai.net/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1219826651.ff.php
- http://www.shinnai.net/xplits/TXT_RvfuIrwypWLMaiVn33Iy.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44749
- https://www.exploit-db.com/exploits/6318
- http://secunia.com/advisories/31632
- http://securityreason.com/securityalert/4200
- http://www.securityfocus.com/bid/30861
- http://www.shinnai.net/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1219826651.ff.php
- http://www.shinnai.net/xplits/TXT_RvfuIrwypWLMaiVn33Iy.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44749
- https://www.exploit-db.com/exploits/6318
→ the Explorer · watch your stack · NVD