CVE-2008-4384 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 28.7% (pctl 98)
Patch early
A public exploit exists.
Description
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) enableZoomPastMax methods.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 28.71% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-10-07 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| iseemedia | lpviewer |
| mgi software | lpviewer |
| roxio | lpviewer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | iseemedia / Roxio / MGI Software LPViewer - ActiveX Control Buffer Overflow (Metasploit) | 2010-05-09 |
References
- http://secunia.com/advisories/32140
- http://www.kb.cert.org/vuls/id/848873
- http://www.securityfocus.com/bid/31604
- http://www.vupen.com/english/advisories/2008/2749
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45699
- http://secunia.com/advisories/32140
- http://www.kb.cert.org/vuls/id/848873
- http://www.securityfocus.com/bid/31604
- http://www.vupen.com/english/advisories/2008/2749
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45699
→ the Explorer · watch your stack · NVD