peter bassill · operator
$ cve CVE-2008-4453 JSON

CVE-2008-4453 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 10.5% (pctl 96)

Patch early

A public exploit exists.

Description

The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS10.47% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2008-10-06
Last modified2026-06-16

Affected (2)

VendorProduct
dspicturelight imaging toolkit
dspicturepro imaging sdk

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD