CVE-2008-4771 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 7.1% (pctl 94)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3) Vivotek RTSP MPEG4 SP Control (RtspVapgDecoderNew.dll 2.0.0.39), and possibly other products, allows remote attackers to execute arbitrary code via a long Url property. NOTE: some of these details are obtained from third party information.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 7.14% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-10-28 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| 4xem | vatctrl class |
| d-link | mpeg4 shm audio control |
| vivotek | rtsp mpeg4 sp control |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | D-Link MPEG4 SHM Audio Control - 'VAPGDecoder.dll 1.7.0.5' Remote Buffer Overflow | 2008-02-26 |
References
- http://osvdb.org/42378
- http://osvdb.org/43007
- http://secunia.com/advisories/29131
- http://secunia.com/advisories/29145
- http://secunia.com/advisories/29146
- http://securityreason.com/securityalert/4517
- http://www.securityfocus.com/bid/28010
- http://www.vupen.com/english/advisories/2008/0685/references
- http://www.vupen.com/english/advisories/2008/0686/references
- http://www.vupen.com/english/advisories/2008/0687/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40863
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40864
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40867
- https://www.exploit-db.com/exploits/5193
- http://osvdb.org/42378
- http://osvdb.org/43007
- http://secunia.com/advisories/29131
- http://secunia.com/advisories/29145
- http://secunia.com/advisories/29146
- http://securityreason.com/securityalert/4517
→ the Explorer · watch your stack · NVD