peter bassill · operator
$ cve CVE-2008-3878 JSON

CVE-2008-3878 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 36.2% (pctl 98)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS36.23% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2008-09-02
Last modified2026-06-16

Affected (1)

VendorProduct
ultrasharewareultra office control

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD